AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63106

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

ReadyEcommerce versions prior to 4.5.2 are vulnerable to an unauthenticated SQL injection in the product listing API, allowing attackers to exploit the unsanitized rating parameter to execute time-based blind SQL injection. This critical vulnerability can lead to the extraction of sensitive database information, including user credentials and admin password hashes, and may also grant unauthorized file system access due to the database connection operating with root privileges. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of severe data breaches.

CVE
CVE-2026-63106
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%

Original NVD Description

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents, including user credentials and administrator password hashes, with potential additional file system access due to the database connection running as root.