Esokia Labs
  • CVE
  • Research

Information-Disclosure


CVE-2026-39079 - PrestaShop upsshipping Module Sensitive Data Exposure via Publicly Accessible Logs

 Posted on May 18, 2026  |  Esokia (Maxime Morel-Bailly)

An information disclosure vulnerability in the UPS Shipping Module (upsshipping) for PrestaShop, developed by the now-defunct Agence Web 360, allows unauthenticated retrieval of XML log files exposing UPS API credentials, shipper account numbers and customer PII. [Read More]
cve  prestashop  information-disclosure  access-control 

     • © 2026  •  Esokia

    Hugo v0.155.3 powered  •  Theme Beautiful Hugo adapted from Beautiful Jekyll