CVE / Vulnerability Disclosures
Publicly disclosed vulnerabilities I’ve reported, coordinated with vendors under responsible disclosure. Each entry links to the official CVE record and the vendor advisory. Data is maintained in data/cves.yaml.
| CVE | Product | Type | CVSS | Advisory | Date | Write-up |
|---|---|---|---|---|---|---|
| CVE-2026-86665 | aircheng-org iWebShop-5 up to 5.15 | Missing Authorization (CWE-862) | 7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R) | Advisory | 2026-09-08 | โ |
| CVE-2026-86666 | aircheng-org iWebShop-5 up to 5.15 | Unrestricted Upload (CWE-434) | 7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R) | Advisory | 2026-09-08 | โ |
| CVE-2026-86667 | aircheng-org iWebShop-5 up to 5.15 | SQL Injection (CWE-89) | 4.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R) | Advisory | 2026-09-08 | โ |