Looking for the vulnerability index of Invicti's legacy products?
PrestaShop Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2025-25691 - Vulnerability Database

PrestaShop Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2025-25691

Medium
Reference: CVE-2025-25691
Title: PrestaShop Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
Overview:

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.