CVE-2026-96600: Isotope Isotope-Core

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table.

Affected products

  • Isotope Isotope-Core: up to and including 2.9.10

Published 2026-09-23. Last modified 2026-09-24.