NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2271 most downloaded on Packagist
PrestaShop module ps_facetedsearch
Last release 28 days ago
10 Sep 2026
Release timing varies
gaps range from 1 weeks to 8 months
Rarely documented
notes for 11 of 48 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
48 releases · first in 2016
Changes #1324 : Release 5.1.0 by @mattgoud #1327 : Fix PHPStan 2 findings on the develop matrix by @mattgoud #1325 : Bump version to 5.1.0 by @mattgou
One column per quarter.
Changes #1267 : Release 5.0.0 by @tleon #1266 : Bump webpack from 5.107.2 to 5.108.4 by @dependabot #1257 : Assign language to the facets template so
You can download ps_facetedsearch.zip from the Assets section to update the module.
You can download ps_facetedsearch.zip from the Assets section to update the module.
More information about the release:
https://build.prestashop-project.org/news/2026/security-update-faceted-search-module-ps-facetedsearch/
Written by
PrestaShop team
Published
Jun 3, 2026
Share this
A security vulnerability has been identified in the Faceted Search module ( ps_facetedsearch ). Under certain conditions, specially crafted requests could be processed unsafely by the module and lead to the execution of unauthorized code on the server. The issue does not require an account or authentication, so any shop running an affected version is exposed.
A fix is available in version 4.0.4 . If you use ps_facetedsearch , update to this version as soon as possible. This is the only complete way to close the issue.
If you use ps_facetedsearch, updating to v4.0.4 is the recommended next step. The recommendations further down this article add useful extra layers, but the update is what actually closes the issue.
The vulnerability affects ps_facetedsearch 3.0.0 and later , up to and including 4.0.3 , on any shop running PrestaShop 1.7.1.0 or newer .
It is fixed in ps_facetedsearch 4.0.4 .
Full details are tracked in the security advisory .
Because the module is widely installed (it powers product filtering on a large share of PrestaShop stores) and because no authentication is required to reach the issue, we consider this a high-priority update for every merchant using it.
The recommended path is to install the latest version of the module:
In your Back Office, go to Modules and check for available updates for Faceted Search.
Update the module to v4.0.4 .
If the update does not appear yet, you can download it directly from the release page and install it manually.
Download ps_facetedsearch v4.0.4
After updating, confirm that the installed version reported in the Back Office is 4.0.4 (or later).
Updating to v4.0.4 is the recommended action and the only complete remediation. If you are temporarily unable to install the new version (for example, a heavily customized module or a constrained release process), advanced users can apply the official fix directly from the source.
The change is contained in a single commit. Apply it to your installed copy of the module, then redeploy:
View the fix commit
Applying the commit manually closes the same issue, but it leaves you on an older module version that is missing every other fix and improvement shipped since. Treat it as a bridge and schedule the update to v4.0.4 as soon as you can.
If you are not comfortable editing module files on a production shop, do this on a staging copy first, or ask a PrestaShop expert to apply it for you.
Updating closes the vulnerability, but if your shop ran an affected version, it is worth checking for signs that it was already targeted. Connect to your server via FTP or shell access and look for the following:
Unexpected PHP files in the modules/ps_facetedsearch/ directory (and its subdirectories). The module ships a known set of files; any extra or unfamiliar .php file that you did not install is a warning sign.
Unusual entries in your server access logs , in particular repeated or malformed requests targeting files under the modules/ps_facetedsearch/ path.
You can also review the Advanced Parameters > Information page in your Back Office, which lists changed core files, though this check alone is not sufficient to confirm a shop is clean.
If you discover unexpected files, suspicious log activity, or any other sign of compromise, do not assume that updating the module is enough. A shop that has already been breached needs to be investigated and cleaned. Contact a PrestaShop expert, rotate your Back Office passwords once the shop is confirmed clean, and review any other modules and credentials on the server.
These measures add layers of defense and limit the impact of attacks in general. None of them is a substitute for updating ps_facetedsearch to v4.0.4, but together they make your server harder to exploit.
Changes #1197 : Release 4.0.3 by @Hlavtox #1196 : Remove annoying category behavior by @Hlavtox #1195 : feat: added 'actionFacetedSearchCacheKeyGenera
Changes #1187 : Release version 4.0.2 by @Hlavtox #1185 : Bump @babel/core from 7.24.9 to 7.28.5 by @dependabot #1189 : Remove condition to get curren
Changes #1160 : Release 4.0.1 by @Hlavtox #1159 : Bump version to 4.0.1 by @Hlavtox #1156 : Provide proper product order on search page by @Hlavtox #1
Changes #1107 : Release 4.0.0 by @jolelievre #1106 : Bump Version 4.0.0 by @jolelievre #1094 : Fix PHP 8.4 compatibility by @Hlavtox #1091 : Bump @bab
Changes #1044 : Release 3.16.1 by @Progi1984 #1042 : Bump webpack from 5.92.0 to 5.92.1 by @dependabot #1040 : Bump braces from 3.0.2 to 3.0.3 by @dep
data-name to distinguish facet by @Progi1984This release brings a significant performance improvements when listing products.
This release brings a significant performance improvements when listing products.
Changes #994 : Release 3.15.1 by @jolelievre #993 : Bump version 3.15.1 by @jolelievre #990 : Use loose type for Translator by @jolelievre #989 : Bump
Changes #981 : Release 3.15.0 by @jolelievre #983 : Deprecate standalone endpoints to match PrestaShop 9.0 new security policy by @jolelievre #979 : M
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →