CVE-2026-86666 | aircheng-org iWebShop-5 up to 5.15 controllers/pic.php upload_json/uploadFile unrestricted upload

SecurityVulns

A vulnerability classified as critical was found in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload.

This vulnerability is identified as CVE-2026-86666. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More