CVE-2026-96600
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
23/09/2026
Last modified:
23/09/2026
Description
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
5.50
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/isotope/core
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/Attribute/Callback.php#L186-L188
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/Attribute/Callback.php#L38
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Backend/ProductPrice/Callback.php#L155-L200
- https://github.com/isotope/core/blob/028d47cbe69c7712339d34539721bea7369dc937/system/modules/isotope/library/Isotope/Widget/MediaManager.php#L468
- https://github.com/isotope/core/issues/2585
- https://www.vulncheck.com/advisories/isotope-ecommerce-through-2.9.10-sql-injection-via-backend-callbacks


