CVE-2026-8772 MEDIUM

CVE-2026-8772: linlinjava litemall Admin Endpoint sql injection

Vendor Linlinjava
Product litemall
Weakness CWE-89 · SQLi
Published May 17, 2026
Last update May 18, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.

Key dates

Disclosure timeline

May 17, 2026 CVE published
May 18, 2026 Record updated