CVE / Vulnerability Disclosures

Publicly disclosed vulnerabilities I’ve reported, coordinated with vendors under responsible disclosure. Each entry links to the official CVE record and the vendor advisory. Data is maintained in data/cves.yaml.

CVEProductTypeCVSSAdvisoryDateWrite-up
CVE-2026-86665aircheng-org iWebShop-5 up to 5.15Missing Authorization (CWE-862)7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R)Advisory2026-09-08โ€”
CVE-2026-86666aircheng-org iWebShop-5 up to 5.15Unrestricted Upload (CWE-434)7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R)Advisory2026-09-08โ€”
CVE-2026-86667aircheng-org iWebShop-5 up to 5.15SQL Injection (CWE-89)4.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R)Advisory2026-09-08โ€”