Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-54159: PrestaShop ps_facetedsearch: Unauthenticated Remote Code Execution
CVE-2026-54159 · published 2 months ago
Summary
A vulnerability in PrestaShop's ps_facetedsearch module allows an attacker to execute code on your server without needing a login. This can happen if you're using a vulnerable version of the module and a customer or attacker crafts a specific URL request. To fix this, you should upgrade the ps_facetedsearch module to the latest version. If you can't upgrade, you can apply a manual fix by changing a line of code in the Block.php file.
What to do
- Update prestashop ps_facetedsearch to version 4.0.4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| composer | prestashop | ps_facetedsearch |
>= 3.0.0, < 4.0.4 Fix: upgrade to 4.0.4
|
| – | prestashop | ps_facetedsearch | >= 3.0.0, < 4.0.4 |
Original advisory text
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
### Impact
A PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`.
The module rebuilds the selected search filters from the request URL. The value of a slider filter (**price** or **weight**) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native `unserialize()`.
By crafting that value, an attacker can smuggle a malicious serialized PHP object into the cache. When it is deserialized, a gadget chain writes an arbitrary PHP file inside the module directory, which is then used as a webshell to run commands on the server.
### Who is impacted
Any shop using a vulnerable version of `ps_facetedsearch` that displays a filter template containing a slider filter (price or weight). Exploitation is remote and **unauthenticated**, a single crafted front-office request is enough, and leads to remote code
execution and full compromise of the shop and its server.
**Affected versions:** `3.0.0` through `4.0.3` (all versions since 3.0.0, including the latest release).
### Patches
Upgrade the `ps_facetedsearch` module to the patched version. Upgrading the module is the best action that removes the vulnerability.
Otherwise, you can apply the fix manually in the file `src/Filters/Block.php`:
In the `getFromCache()` method, replace the native `unserialize()` call:
```php
// Before
if (!empty($row)) {
return unserialize(current($row));
}
// After
if (!empty($row)) {
return \Tools::unSerialize(current($row));
}
```
### Until the module is upgraded:
- Remove price and weight slider filters from the filter templates that are exposed on the
front office.
- Clear the faceted-search filter cache, and audit the `modules/ps_facetedsearch/` directory for
unexpected PHP files.
- Monitor search requests for PHP serialization patterns (`O:`, `;i:`, references to classes such
as `Monolog\…`) and block them at the WAF level.
### Resources
- Thank you to Frédéric Moreau (Antadis) and Gilles Caudal (Datalinx) for reporting this vulnerability.
A PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`.
The module rebuilds the selected search filters from the request URL. The value of a slider filter (**price** or **weight**) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native `unserialize()`.
By crafting that value, an attacker can smuggle a malicious serialized PHP object into the cache. When it is deserialized, a gadget chain writes an arbitrary PHP file inside the module directory, which is then used as a webshell to run commands on the server.
### Who is impacted
Any shop using a vulnerable version of `ps_facetedsearch` that displays a filter template containing a slider filter (price or weight). Exploitation is remote and **unauthenticated**, a single crafted front-office request is enough, and leads to remote code
execution and full compromise of the shop and its server.
**Affected versions:** `3.0.0` through `4.0.3` (all versions since 3.0.0, including the latest release).
### Patches
Upgrade the `ps_facetedsearch` module to the patched version. Upgrading the module is the best action that removes the vulnerability.
Otherwise, you can apply the fix manually in the file `src/Filters/Block.php`:
In the `getFromCache()` method, replace the native `unserialize()` call:
```php
// Before
if (!empty($row)) {
return unserialize(current($row));
}
// After
if (!empty($row)) {
return \Tools::unSerialize(current($row));
}
```
### Until the module is upgraded:
- Remove price and weight slider filters from the filter templates that are exposed on the
front office.
- Clear the faceted-search filter cache, and audit the `modules/ps_facetedsearch/` directory for
unexpected PHP files.
- Monitor search requests for PHP serialization patterns (`O:`, `;i:`, references to classes such
as `Monolog\…`) and block them at the WAF level.
### Resources
- Thank you to Frédéric Moreau (Antadis) and Gilles Caudal (Datalinx) for reporting this vulnerability.
References
- https://github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-m5f5-28q...
- https://github.com/advisories/GHSA-m5f5-28qr-9g9r
- https://github.com/PrestaShop/ps_facetedsearch/commit/9ca839fac68a60641d8187a3ff...
- https://github.com/PrestaShop/ps_facetedsearch/releases/tag/v4.0.4
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54159... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54159 Vendor Advisory
Severity
10.0
Critical
CVSS 3.1: 10.0 (GHSA)
Exploitation
EPSS <1%
Type
CWE-74Injection
Timeline
Published10 Jul 2026
Updated27 Sep 2026
First seen10 Jul 2026
Track software like this
Free during beta