CVE-2026-63106 is a critical unauthenticated SQL injection vulnerability in ReadyEcommerce before version 4.5.2. The vulnerability exists in the product listing API, specifically in the ProductController.php file, where the rating parameter is concatenated directly into a MySQL HAVING clause without parameterization. This allows attackers to perform time-based blind SQL injection to extract the full datab [truncated]
CVE-2026-63105 is a stored cross-site scripting (XSS) vulnerability in ReadyEcommerce before version 4.5.2. The vulnerability allows authenticated customers to inject malicious HTML payloads through chat and support ticket messaging systems. Attackers can submit crafted message content that executes arbitrary JavaScript in the browser of shop owners or administrators who view the message, enabling session [truncated]