Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
ReadyEcommerce before version 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API. The rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can exploit this through time-based blind SQL injection to extract database contents and gain potential file system access due to the database connection running as root.
An unauthenticated attacker over the network can perform SQL injection through the unsanitized rating parameter to extract the full database contents including user credentials and administrator password hashes, and potentially execute OS commands via file system access since the database connection runs as root.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Upgrade ReadyEcommerce to version 4.5.2 or later. Implement parameterized queries for all database operations, particularly in ProductController.php. Apply input validation and sanitization to all API parameters. Restrict database user privileges to the minimum required (avoid running database connections as root). Deploy a Web Application Firewall (WAF) to detect and block SQL injection attempts. Conduct a security audit of the product listing API and related endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-63106
Feedly found the first article mentioning CVE-2026-63106 . See article
A CVSS base score of 9.8 has been assigned.
GitHub Advisories released a security advisory .
A critical unauthenticated SQL injection vulnerability, with a CVSS score of 9.8, affects ReadyEcommerce installations prior to version 4.5.2, allowing attackers to extract sensitive database contents and potentially access the file system. There are no public proof-of-concept exploits available, but users are urged to upgrade to the patched version to mitigate this risk. The vulnerability is particularly dangerous due to its remote exploitability and lack of authentication requirements. See article
CVE-2026-63106 - Exploits & Severity - Feedly
ReadyEcommerce Critical Unauthenticated SQLi (CVE-2026-63106)
CVE-2026-63106 - Exploits & Severity - Feedly
Critical RCE in SPIP SQLite via Code Injection (CVE-2026-66738)
ReadyEcommerce Critical Unauthenticated SQLi (CVE-2026-63106)
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
