CVE-2026-86667 | aircheng-org iWebShop-5 up to 5.15 controllers/member.php member_list Search sql injection
A vulnerability, which was classified as problematic, has been found in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection.
This vulnerability is tracked as CVE-2026-86667. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More