CVE-2026-0843 is a SQL injection vulnerability affecting jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food products up to version 20260103. Specifically, manipulating the 'latitude' argument in the /index.php/api/product.category/index file allows for remote exploitation. Rated Medium severity (CVSS 6.3), this vulnerability has low attack complexity and can lead to partial loss of confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jiujiujia | Jjjfood | 20260103CNA affected | |
| Victor123 | Jjjfood | 20260103CNA affected | |
| Wxw850227 | Jjjfood | 20260103CNA affected | |
| Jiujiujia | Jjjshop Food | 20260103CNA affected | |
| Victor123 | Jjjshop Food | 20260103CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.