Stored Cross-Site Scripting Vulnerability in ReadyEcommerce by CodeCanyon
CVE-2026-63105
5.1MEDIUM
What is CVE-2026-63105?
ReadyEcommerce versions prior to 4.5.2 are susceptible to a stored cross-site scripting (XSS) vulnerability. This flaw allows authenticated customers to inject malicious HTML content into chat and support ticket messages. The vulnerability arises from unsanitized rendering in specific components, such as Messages.vue, RightChatSidebar.vue, SupportTicketMessages.vue, and SupportTicketDetails.vue. An attacker can leverage this vulnerability to submit specially crafted messages that execute arbitrary JavaScript in the browsers of shop owners or administrators viewing the messages, leading to potential session cookie theft and unauthorized account access.
Affected Version(s)
Ready eCommerce 0
