Known security flaws, explained from what you're seeing
Nobody types "CVE-2024-XXXXX" into Google when their store stops working properly. They type "my site redirects to a casino site" or "strange orders are appearing in my back office". This section starts from what you're actually seeing and works back to the technical flaw, never the other way round.
How to use this section
Each page below starts from a concrete symptom or a category of flaw and explains, in plain language, what's actually happening, how to check whether you're affected, and what to do. None of these pages give an attack method, a working exploit, or a tool for targeting a site: the content is strictly defensive, written for a merchant who needs to understand their situation and act, not for someone looking to exploit a flaw.
When a vulnerability identifier (CVE) or a specific version is cited, it's because it was verified against a reliable public source, named in the text. Where a technical point is uncertain, the page stays deliberately general rather than making an unverified claim: wrong information about a security flaw is worse than no information, because it can make you believe you're protected when you aren't.
What you've noticed on your store
-
My site redirects to an unknown site
A visitor lands on the store and ends up elsewhere, sometimes only on mobile.
-
Spam pages in my Google results
Pages you never wrote appear under your own domain name.
-
My host has suspended my site
An email announces a suspension for "suspicious activity", with no other detail.
-
Suspicious orders or customer accounts
A burst of failed orders, or dozens of accounts created overnight.
-
An unknown file on the server
A strangely named PHP file sitting in a folder that should only hold images.
-
My site is sending emails I didn't write
Customers report a promotional message coming from your domain.
-
My antivirus blocks my own site
Chrome or a visitor's antivirus shows a danger warning.
Understanding the kind of flaw involved
-
SQL injections
What they actually are, and how to check whether your store is affected.
-
Abandoned modules and extensions
The real first entry point, ahead of a weak password.
-
Admin passwords and shared access
Human flaws, not technical ones, and among the easiest to fix.
-
File permissions on shared hosting
How an infection can spread from one site to another on the same server.
-
End-of-life PHP versions
A version that "still works" no longer receives any security fix.
Check, react, clean up, protect
-
Checking if your site is compromised, without paid tools
The free checks to run before considering a paid audit.
-
What to do in the first two hours
The exact order of priorities once the doubt has just been confirmed.
-
Cleaning up an infected site
The method, and why restoring a backup isn't always enough.
-
Staying protected after a cleanup
What has to change structurally to avoid a repeat.
-
Tracking published vulnerabilities
Where to follow flaws affecting what you actually use.
Frequently asked questions
How do I know which page in this section applies to me?
Are these pages enough to clean my site myself?
Why are some of the flaws mentioned several years old?
Does this section only cover PrestaShop and WordPress?
What if no page matches my exact situation?
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.