← Back to the live CVE advisory feed

CVE-2026-7848: raty

Severity
8.6 (HIGH)
Vendor
ALIOR BANK
Affected versions
8.0.0 through before 8.1.11; 9.0.0 through before 9.0.7
Patch status
Unknown
Published
2026-09-14T15:17:08.560
Modified
2026-09-14T15:17:08.560

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The module inserts values of the POST parameters "alior_product_promotion",  "alior_category_promotion" and "alior_category_enabled" directly into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit functionality in the PrestaShop backoffice can inject arbitrary SQL, potentially allowing unauthorized access to and modification of database contents. This issue was fixed in versions: 9.0.7 and 8.1.11

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 14, 2026 04:00 PM UTC
334 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-81648
CryptoPayment Gateway
Reporter: CONTACT
10
CRITICAL
VIEW RECORD
CVE-2026-82434
Apache Storm Nimbus PATCH
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-90898
Bifrost
Reporter: REEFS
9.8
CRITICAL
VIEW RECORD
CVE-2026-57123
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57125
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-21391
PingAM
Reporter: RESPONSIBLE-DISCLOSURE
9.5
CRITICAL
VIEW RECORD
CVE-2026-90680
DIR-823G
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-85192
Conditional Content Pro extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-90692
DIR-878
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-90693
DIR-878
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-90937
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-90919
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-90961
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
9.3
CRITICAL
VIEW RECORD
CVE-2026-12258
REST API
Reporter: CVE-COORDINATION
9.2
CRITICAL
VIEW RECORD
CVE-2026-74933
GenieWords
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-85129
Hoo Companion
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-88793
YouTube Embed
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2023-46273
Product identification pending PATCH
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2023-50461
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-90938
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-82762
FXA5000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82766
SGA1000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82770
RP-WAH-SR1
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82772
ECE1000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82774
M2M Gateway Integrated Type CPS-MG341*
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82777
Integrated Type CPS-PC341[][]-*-9201
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82779
CPS-TM341G5MB-ADSC1-931
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82780
CPS-TM341G5MB-ADSC1-931
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82787
CPSL-08P1EN
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82789
CONPROSYS HMI System(CHS)
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82791
CAN-2-WF
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82794
SV-CPT-MC310
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-90689
W20E
Reporter: CNA
8.7
HIGH
VIEW RECORD
CVE-2026-89180
Product identification pending
Reporter: TWCERT
8.7
HIGH
VIEW RECORD
CVE-2026-90934
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90605
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90606
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90607
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90608
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2023-45858
Product identification pending PATCH
Reporter: CVE
8.6
HIGH
VIEW RECORD
CVE-2026-82765
FXA5000
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-82768
SGA1000
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-82793
CAN-2-WF
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-90699
DWR-M920
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-78375
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-90932
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-15600
raty
Reporter: CVD
8.6
HIGH
VIEW RECORD
CVE-2026-7848
raty PATCH
Reporter: CVD
8.6
HIGH
VIEW RECORD
CVE-2026-12518
Product identification pending
Reporter: CVE-COORDINATION
8.5
HIGH
VIEW RECORD
CVE-2026-90702
DWR-M921
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-90703
DWR-M921
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-20773
Product identification pending
Reporter: RESPONSIBLE-DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-57126
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-68955
The installer for Rakuten Kobo Desktop Application (Windows version)
Reporter: VULTURES
8.4
HIGH
VIEW RECORD
CVE-2026-90895
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.4
HIGH
VIEW RECORD
CVE-2024-58383
Product identification pending PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-82786
Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*
Reporter: VULTURES
8.2
HIGH
VIEW RECORD
CVE-2026-37008
CrewAI
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-25687
Product identification pending
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-57130
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-59569
Product identification pending
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-23789
Exynos 850 firmware
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-90894
Parallels Desktop for Mac PATCH
Reporter: REEFS
7.8
HIGH
VIEW RECORD
CVE-2026-90948
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-90949
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-29811
Product identification pending PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-31278
BioStar 2 PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-90930
Product identification pending
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-88802
MDJM Event Management PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-15891
Product identification pending
Reporter: VULNERABILITIES
7.5
HIGH
VIEW RECORD
CVE-2026-33963
Exynos 1330 firmware
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2023-32803
ca-certificates
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-85189
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85190
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85191
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85195
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88852
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88853
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-57129
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-59570
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-36453
Product identification pending PATCH
Reporter: CVE
7.4
HIGH
VIEW RECORD
CVE-2026-73195
Product identification pending PATCH
Reporter: SECURITY
7.3
HIGH
VIEW RECORD
CVE-2023-28148
Product identification pending PATCH
Reporter: CVE
7.2
HIGH
VIEW RECORD
CVE-2026-90929
filebrowser
Reporter: DISCLOSURE
7.2
HIGH
VIEW RECORD
CVE-2026-90688
W20E
Reporter: CNA
7.1
HIGH
VIEW RECORD
CVE-2026-8821
Product identification pending
Reporter: RESPONSIBLEDISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90927
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90928
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90933
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90939
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-71198
Product identification pending PATCH
Reporter: CVE
7
HIGH
VIEW RECORD
CVE-2026-81564
Product identification pending
Reporter: SECURITY
7
HIGH
VIEW RECORD
CVE-2026-90593
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90596
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90601
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90603
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-82784
Product identification pending
Reporter: VULTURES
6.9
MEDIUM
VIEW RECORD
CVE-2026-85188
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD
CVE-2026-79700
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD
CVE-2026-81565
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.