SQL Injection Vulnerability in linlinjava litemall Admin Endpoint
CVE-2026-8772
Key Information:
- Vendor
Linlinjava
- Status
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2026-8772?
A vulnerability has been discovered in the linlinjava litemall product, particularly affecting its Admin Endpoint. This weakness allows for potential SQL injection attacks, which can be initiated remotely. The exploitation of this vulnerability could compromise the integrity of the database by manipulating queries. Despite early disclosure attempts, the vendor has not responded to the reports of this security issue. Users of versions up to 1.8.0 are urged to assess their environments for potential risks.
Affected Version(s)
litemall 1.0
litemall 1.1
litemall 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
