CVE Feed

    Dashboard / CVE / CVE-2026-63106

    CVE-2026-63106

    ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents, including user credentials and administrator password hashes, with potential additional file system access due to the database connection running as root.

    Published:Aug 10, 2026
    Last Modified:Aug 11, 2026
    EPS:Aug 10, 2026
    EPSS Score:0.00292
    CVSS Score:9.8

    Affected Products

    Vendor
    Razinsoft
    Product
    Ready Ecommerce

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High