E107

E107

84 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 11.08.2026 11:14:15
  • Zuletzt bearbeitet 03.09.2026 17:51:18

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can...

  • EPSS 0.4%
  • Veröffentlicht 30.07.2026 13:41:34
  • Zuletzt bearbeitet 30.07.2026 16:45:00

e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs col...

  • EPSS 0.75%
  • Veröffentlicht 17.06.2026 21:42:59
  • Zuletzt bearbeitet 23.06.2026 15:44:39

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path...

  • EPSS 0.13%
  • Veröffentlicht 26.05.2026 15:04:32
  • Zuletzt bearbeitet 24.07.2026 11:10:00

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check() handles CSRF tokens. Instead of requiring a toke...

  • EPSS 0.3%
  • Veröffentlicht 26.05.2026 15:01:36
  • Zuletzt bearbeitet 24.07.2026 11:10:00

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This ...

  • EPSS 0.18%
  • Veröffentlicht 26.05.2026 14:54:21
  • Zuletzt bearbeitet 24.07.2026 11:10:00

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by others. This stems from inadequate server-side access c...

  • EPSS 0.19%
  • Veröffentlicht 26.05.2026 14:51:49
  • Zuletzt bearbeitet 24.07.2026 11:10:00

e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vul...

Exploit
  • EPSS 1.13%
  • Veröffentlicht 13.01.2026 22:52:03
  • Zuletzt bearbeitet 20.01.2026 18:03:06

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 13.01.2026 22:51:52
  • Zuletzt bearbeitet 16.01.2026 19:16:13

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL pa...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 13.01.2026 22:51:49
  • Zuletzt bearbeitet 16.01.2026 19:16:12

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload ...