CVE-2026-86668 | aircheng-org iWebShop-5 up to 5.15 controllers/pic.php uploadFile outerSrc/selectPhoto cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting.

This vulnerability is listed as CVE-2026-86668. The attack may be performed from remote. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More