CVE-2026-96600: Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tluser table.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be an authenticated Contao backend user and have permissions for the Isotope module. Unauthenticated external users are not described as able to exploit it.
What access and interaction are required for exploitation?
Exploitation requires backend access with Isotope module permissions and the ability to supply request-controlled identifiers. No victim interaction is required.
What data could be exposed?
The injection can be used with conditional or time-based payloads to extract arbitrary database contents. This includes user password hashes stored in the tl_user table.
Which releases are affected?
Isotope eCommerce through version 2.9.10 is affected.