PatchSiren

Razinsoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Razinsoft CVE published 2026-08-10

CVE-2026-63106

CVE-2026-63106 is a critical unauthenticated SQL injection vulnerability in ReadyEcommerce before version 4.5.2. The vulnerability exists in the product listing API, specifically in the ProductController.php file, where the rating parameter is concatenated directly into a MySQL HAVING clause without parameterization. This allows attackers to perform time-based blind SQL injection to extract the full datab [truncated]

MEDIUM Razinsoft CVE published 2026-08-10

CVE-2026-63105

CVE-2026-63105 is a stored cross-site scripting (XSS) vulnerability in ReadyEcommerce before version 4.5.2. The vulnerability allows authenticated customers to inject malicious HTML payloads through chat and support ticket messaging systems. Attackers can submit crafted message content that executes arbitrary JavaScript in the browser of shop owners or administrators who view the message, enabling session [truncated]