iWebShop-5 vulnerabilities
CVEs whose affected-version data names the iWebShop-5 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-86670Low· 3.7PoCA flaw has been found in aircheng-org iWebShop-5 up to 5.15
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…
CVE-2026-86669High· 7.3PoCA vulnerability was detected in aircheng-org iWebShop-5 up to 5.15
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possib…
CVE-2026-86668Medium· 4.3PoCA security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15
A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site…
CVE-2026-86667Medium· 4.7PoCA weakness has been identified in aircheng-org iWebShop-5 up to 5.15
A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possi…
CVE-2026-86666High· 7.3PoCA security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remot…
CVE-2026-86665High· 7.3PoCA vulnerability was identified in aircheng-org iWebShop-5 up to 5.15
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is…