HIGH 7.0 NVD
CVE-2026-96600
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administr
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table.
References
- https://github.com/isotope/core
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modul
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modul
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modul
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modul
This high severity vulnerability with a CVSS score of 7.0 was published on 2026-09-23 via NVD.
vulnfeed aggregates 12912 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.