PatchSiren

Alior Bank CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Alior Bank CVE published 2026-09-14

CVE-2026-7848

CVE-2026-7848 is a SQL Injection vulnerability in the Alior Bank PrestaShop module 'raty' for commercial partners. The module inserts values of POST parameters directly into SQL UPDATE queries without sanitization or validation, allowing an attacker with access to product or category add/edit functionality in the PrestaShop backoffice to inject arbitrary SQL. This issue was fixed in versions 9.0.7 and 8.1.11.

HIGH Alior Bank CVE published 2026-09-14

CVE-2026-15600

CVE-2026-15600 SQL Injection vulnerability in Alior Bank PrestaShop module 'raty'. The module is used by Alior Bank for commercial partners and is vulnerable in the toggleCategoryPromotionAction method, allowing an attacker with access to the PrestaShop backoffice to inject arbitrary SQL code, potentially leading to unauthorized access and modification of database contents. PrestaShop users with the 'raty [truncated]