CVE-2026-86668
A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the fil
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-79 · CWE-94
Sin historial EPSS suficiente todavía.
A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-818244.7 MED—
———The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.3hCVE-2026-784638.8 ALT—
———Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.2hCVE-2026-779088.8 ALT—
———Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.2hCVE-2026-761918.2 ALT—
———Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.2hCVE-2026-698067.0 ALT—
———Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.2hCVE-2026-696904.6 MED—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.2h