SQL Injection Vulnerability in Linlinjava Litemall Front-end WeChat API
CVE-2026-8771
Key Information:
- Vendor
Linlinjava
- Status
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2026-8771?
A security flaw has been identified in the Linlinjava Litemall affecting the Front-end WeChat API. The vulnerability is located in the 'WxGoodsController' function of the component, allowing an attacker to exploit SQL injection techniques. This flaw can be remotely exploited, making it critical for users of Litemall versions up to 1.8.0 to assess their exposure and implement security measures. Despite early notifications to the vendor, no response has been recorded regarding the mitigation of this vulnerability.
Affected Version(s)
litemall 1.0
litemall 1.1
litemall 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
