Available for projects & agency overflow · Quick reply, from the person who does the work

Known security flaws, explained from what you're seeing

Nobody types "CVE-2024-XXXXX" into Google when their store stops working properly. They type "my site redirects to a casino site" or "strange orders are appearing in my back office". This section starts from what you're actually seeing and works back to the technical flaw, never the other way round.

Describe my issue Chat on WhatsApp

How to use this section

Each page below starts from a concrete symptom or a category of flaw and explains, in plain language, what's actually happening, how to check whether you're affected, and what to do. None of these pages give an attack method, a working exploit, or a tool for targeting a site: the content is strictly defensive, written for a merchant who needs to understand their situation and act, not for someone looking to exploit a flaw.

When a vulnerability identifier (CVE) or a specific version is cited, it's because it was verified against a reliable public source, named in the text. Where a technical point is uncertain, the page stays deliberately general rather than making an unverified claim: wrong information about a security flaw is worse than no information, because it can make you believe you're protected when you aren't.

What you've noticed on your store

Understanding the kind of flaw involved

Check, react, clean up, protect

Frequently asked questions

How do I know which page in this section applies to me?
Start from what you're actually observing, not what you think the cause is. The "by symptom" pages exist for exactly that: describe what's happening, and the matching page works back to the most likely technical causes.
Are these pages enough to clean my site myself?
Some basic checks, yes, particularly the page on free tools. A full cleanup generally needs access to the files and database plus experience spotting backdoors, which goes beyond reading alone.
Why are some of the flaws mentioned several years old?
Because they remain useful for understanding a mechanism, and because stores still running old, unpatched versions can still be exposed to them today. Every flaw cited is dated and sourced to avoid any confusion with an unverified current risk.
Does this section only cover PrestaShop and WordPress?
Those are the two platforms covered here, but several of the mechanisms explained (SQL injection, abandoned modules, file permissions, end-of-life PHP) apply to more or less any CMS built on PHP and a database.
What if no page matches my exact situation?
Describe the situation through the contact form: a direct diagnosis is often faster than trying to match a specific case to a general page.

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

constat
plateforme
depuis-quand (facultatif)
sauvegarde
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.