CVE-2026-7848 is a SQL Injection vulnerability in the Alior Bank PrestaShop module 'raty' for commercial partners. The module inserts values of POST parameters directly into SQL UPDATE queries without sanitization or validation, allowing an attacker with access to product or category add/edit functionality in the PrestaShop backoffice to inject arbitrary SQL. This issue was fixed in versions 9.0.7 and 8.1.11.
CVE-2026-15600 SQL Injection vulnerability in Alior Bank PrestaShop module 'raty'. The module is used by Alior Bank for commercial partners and is vulnerable in the toggleCategoryPromotionAction method, allowing an attacker with access to the PrestaShop backoffice to inject arbitrary SQL code, potentially leading to unauthorized access and modification of database contents. PrestaShop users with the 'raty [truncated]