CVE-2026-86666
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- CWE
- CWE-434, CWE-284
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
- aircheng-org iWebShop-5
Weakness type
Related vulnerabilities
- CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page
- CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173),...
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
- CVE-2026-86239 — liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
- CVE-2026-44402 — Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi