PT-2026-69844 · Unknown · Ready Ecommerce

·

CVE-2026-63105

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ReadyEcommerce versions prior to 4.5.2
Description Authenticated customers can inject malicious HTML payloads through the chat and support ticket messaging systems. This occurs due to unsanitized rendering via the v-html directive in the following files: Messages.vue, RightChatSidebar.vue, SupportTicketMessages.vue, and SupportTicketDetails.vue. An attacker can submit crafted message content that executes arbitrary JavaScript in the browser of a shop owner or administrator who views the message, potentially leading to session cookie theft and account takeover.
Recommendations Update to version 4.5.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63105

Affected Products

Ready Ecommerce