SQL Injection Vulnerability in aircheng-org iWebShop-5
CVE-2026-86667
Key Information:
- Vendor
Aircheng-org
- Status
- Vendor
- CVE Published:
- 8 September 2026
Badges
What is CVE-2026-86667?
A critical vulnerability has been discovered in aircheng-org's iWebShop-5 versions up to 5.15, specifically within the member_list function found in controllers/member.php. This flaw allows attackers to manipulate the Search argument, leading to SQL injection that can be executed remotely. The vulnerability is publicly known, and exploits have been made available, posing significant risk to affected installations. Despite prior notification of the issue, the project maintainers have yet to respond effectively, increasing the urgency for users to address this vulnerability.
Affected Version(s)
iWebShop-5 5.0
iWebShop-5 5.1
iWebShop-5 5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
