CVE-2026-86668
Deferred Deferred - Pending Action

Cross-Site Scripting in iWebShop-5 File Upload

Vulnerability report for CVE-2026-86668, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulDB

Description

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aircheng-org iwebshop to 5.15 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in the aircheng-org iWebShop-5 software up to version 5.15. It exists in the uploadFile function of the controllers/pic.php file. An attacker can exploit this by manipulating the outerSrc/selectPhoto parameter to inject malicious scripts. The attack can be executed remotely and has been publicly disclosed.

Detection Guidance

This vulnerability involves a reflected cross-site scripting (XSS) flaw in the uploadFile function of controllers/pic.php in iWebShop-5 versions up to 5.15. To detect it, inspect web server logs for unusual requests targeting the pic.php endpoint with parameters like outerSrc or selectPhoto. Check for JavaScript code in URL parameters or form submissions.

Impact Analysis

This XSS vulnerability could allow attackers to execute arbitrary scripts in a victim's browser when they access a compromised page. This may lead to theft of session cookies, account hijacking, or defacement of web pages. Users of affected iWebShop-5 versions are at risk if the software is exposed to untrusted input.

Mitigation Strategies

Immediately update iWebShop to the latest version if available. If no update exists, disable the uploadFile function in controllers/pic.php or restrict access to it. Implement input validation and output encoding for all user-supplied data. Use a web application firewall to block malicious requests targeting this flaw.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86668. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart