MEDIUMVulnerability

CVE-2026-86668

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-86668
signal_observed_at
2026-09-16T21:37:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
published_at
2026-09-08T17:18:40.210
last_modified
2026-09-11T21:17:47.733

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86668 — Ninja Signal Threat Intelligence | Ninja Signal