E107

E107 Cms

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 13.01.2026 22:52:03
  • Zuletzt bearbeitet 20.01.2026 18:03:06

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 13.01.2026 22:51:52
  • Zuletzt bearbeitet 16.01.2026 19:16:13

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL pa...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 13.01.2026 22:51:49
  • Zuletzt bearbeitet 16.01.2026 19:16:12

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 13.01.2026 22:51:48
  • Zuletzt bearbeitet 21.01.2026 15:16:05

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 13.01.2026 22:51:48
  • Zuletzt bearbeitet 16.01.2026 19:16:12

e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files wi...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 19.10.2025 15:32:10
  • Zuletzt bearbeitet 12.01.2026 16:42:12

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing manipulation of the argument multiaction[] results in path tr...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.09.2023 14:15:25
  • Zuletzt bearbeitet 21.11.2024 08:24:56

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 28.09.2023 14:15:25
  • Zuletzt bearbeitet 21.11.2024 08:24:56

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.