CERT Polska reported two SQL injection vulnerabilities in the Alior Bank “raty” installment-payment module for PrestaShop. The issues are tracked as CVE-2026-7848 and CVE-2026-15600.
The available disclosures do not identify affected module versions, vulnerable request parameters, severity ratings, evidence of exploitation, or remediation measures. Organizations using the module should identify deployed versions and consult Alior Bank and CERT Polska advisories for fixes or mitigations.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-7848 was detailed as an SQL injection in the Alior Bank PrestaShop raty module's product and category update/addition hooks, where several promotion and category POST parameters are inserted into SQL UPDATE queries without validation. Exploitation requires relevant PrestaShop back-office edit access; the issue was fixed in module versions 9.0.7 and 8.1.11.
CVE-2026-15600 was detailed as an SQL injection flaw in the Alior Bank PrestaShop raty module's toggleCategoryPromotionAction method, where the status POST parameter is inserted into UPDATE queries without validation. An attacker with product or category add/edit access in the PrestaShop back office could inject SQL to access or modify database contents.
CERT Polska received a report of two SQL injection vulnerabilities in the Alior Bank “raty” module for PrestaShop, identified as CVE-2026-7848 and CVE-2026-15600.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcemalware.news
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.