Junglewise Threat Intelligence

CVE-2025-10969: Farktor Software E-Commerce Package SQL injection

CVE-2025-10969 · Severity: critical · CVSS 9.8 · Published 2026-02-12

Technologies: Farktor Software E-Commerce Services Inc. E-Commerce Package. Vendors: Farktor.

Executive brief

Farktor Software's E-Commerce Package, a platform used for managing online retail stores, contains a critical security flaw. This vulnerability allows remote attackers to manipulate database queries without needing any login credentials. An exploit could lead to the theft of sensitive customer data, modification of product or pricing information, or a complete shutdown of the online store.

Technical details

A Blind SQL Injection vulnerability exists in Farktor Software E-Commerce Services Inc. E-Commerce Package due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send crafted SQL queries to the application. Because it is a 'blind' injection, the attacker can infer data by observing differences in application responses or timing. This can result in full unauthorized access to the underlying database, including sensitive user information and administrative credentials. The issue affects versions through 27112025.

Affected products

  • Farktor Software E-Commerce Services Inc. E-Commerce Package through 27112025

Timeline

  • 2026-02-12: disclosed
  • 2026-02-12: advisory

References

Related threats