# Known security flaws, explained from what you're seeing

> Nobody types "CVE-2024-XXXXX" into Google when their store stops working properly. They type "my site redirects to a casino site" or "strange orders are appearing in my back office". This section starts from what you're actually seeing and works back to the technical flaw, never the other way round.

- Source canonique : [https://allaux.fr/en/securite](https://allaux.fr/en/securite)
- Langue : EN
- Dernière mise à jour : 2026-08-03

## How to use this section

Each page below starts from a concrete symptom or a category of flaw and explains, in plain language, what's actually happening, how to check whether you're affected, and what to do. None of these pages give an attack method, a working exploit, or a tool for targeting a site: the content is strictly defensive, written for a merchant who needs to understand their situation and act, not for someone looking to exploit a flaw.

When a vulnerability identifier (CVE) or a specific version is cited, it's because it was verified against a reliable public source, named in the text. Where a technical point is uncertain, the page stays deliberately general rather than making an unverified claim: wrong information about a security flaw is worse than no information, because it can make you believe you're protected when you aren't.

## What you've noticed on your store

- **My site redirects to an unknown site** — A visitor lands on the store and ends up elsewhere, sometimes only on mobile. ([/securite/site-redirige-vers-site-inconnu](/securite/site-redirige-vers-site-inconnu))
- **Spam pages in my Google results** — Pages you never wrote appear under your own domain name. ([/securite/pages-de-spam-dans-google](/securite/pages-de-spam-dans-google))
- **My host has suspended my site** — An email announces a suspension for "suspicious activity", with no other detail. ([/securite/hebergeur-a-suspendu-mon-site](/securite/hebergeur-a-suspendu-mon-site))
- **Suspicious orders or customer accounts** — A burst of failed orders, or dozens of accounts created overnight. ([/securite/commandes-comptes-clients-suspects](/securite/commandes-comptes-clients-suspects))
- **An unknown file on the server** — A strangely named PHP file sitting in a folder that should only hold images. ([/securite/fichier-inconnu-sur-le-serveur](/securite/fichier-inconnu-sur-le-serveur))
- **My site is sending emails I didn't write** — Customers report a promotional message coming from your domain. ([/securite/mon-site-envoie-des-emails-que-je-n-ai-pas-ecrits](/securite/mon-site-envoie-des-emails-que-je-n-ai-pas-ecrits))
- **My antivirus blocks my own site** — Chrome or a visitor's antivirus shows a danger warning. ([/securite/antivirus-navigateur-bloque-mon-site](/securite/antivirus-navigateur-bloque-mon-site))

## Understanding the kind of flaw involved

- **SQL injections** — What they actually are, and how to check whether your store is affected. ([/securite/injections-sql-expliquees](/securite/injections-sql-expliquees))
- **Abandoned modules and extensions** — The real first entry point, ahead of a weak password. ([/securite/modules-et-extensions-abandonnes](/securite/modules-et-extensions-abandonnes))
- **Admin passwords and shared access** — Human flaws, not technical ones, and among the easiest to fix. ([/securite/mots-de-passe-administration-acces-partages](/securite/mots-de-passe-administration-acces-partages))
- **File permissions on shared hosting** — How an infection can spread from one site to another on the same server. ([/securite/droits-de-fichiers-hebergement-mutualise](/securite/droits-de-fichiers-hebergement-mutualise))
- **End-of-life PHP versions** — A version that "still works" no longer receives any security fix. ([/securite/versions-de-php-en-fin-de-vie](/securite/versions-de-php-en-fin-de-vie))

## Check, react, clean up, protect

- **Checking if your site is compromised, without paid tools** — The free checks to run before considering a paid audit. ([/securite/verifier-si-mon-site-est-compromis](/securite/verifier-si-mon-site-est-compromis))
- **What to do in the first two hours** — The exact order of priorities once the doubt has just been confirmed. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Cleaning up an infected site** — The method, and why restoring a backup isn't always enough. ([/securite/nettoyer-un-site-infecte](/securite/nettoyer-un-site-infecte))
- **Staying protected after a cleanup** — What has to change structurally to avoid a repeat. ([/securite/se-proteger-apres-un-nettoyage](/securite/se-proteger-apres-un-nettoyage))
- **Tracking published vulnerabilities** — Where to follow flaws affecting what you actually use. ([/securite/surveiller-les-failles-qui-concernent-ma-boutique](/securite/surveiller-les-failles-qui-concernent-ma-boutique))

## Need hands-on help?

> These pages explain and equip you, they don't replace a diagnosis of your own store. If a compromise is already under way or confirmed, the cleanup and security service handles the concrete case, not just the general explanation.

## FAQ

### How do I know which page in this section applies to me?

Start from what you're actually observing, not what you think the cause is. The "by symptom" pages exist for exactly that: describe what's happening, and the matching page works back to the most likely technical causes.

### Are these pages enough to clean my site myself?

Some basic checks, yes, particularly the page on free tools. A full cleanup generally needs access to the files and database plus experience spotting backdoors, which goes beyond reading alone.

### Why are some of the flaws mentioned several years old?

Because they remain useful for understanding a mechanism, and because stores still running old, unpatched versions can still be exposed to them today. Every flaw cited is dated and sourced to avoid any confusion with an unverified current risk.

### Does this section only cover PrestaShop and WordPress?

Those are the two platforms covered here, but several of the mechanisms explained (SQL injection, abandoned modules, file permissions, end-of-life PHP) apply to more or less any CMS built on PHP and a database.

### What if no page matches my exact situation?

Describe the situation through the contact form: a direct diagnosis is often faster than trying to match a specific case to a general page.
