CVE-2022-50906
- EPSS 0.37%
- Veröffentlicht 13.01.2026 22:51:48
- Zuletzt bearbeitet 16.01.2026 19:16:12
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files wi...
CVE-2022-50905
- EPSS 0.6%
- Veröffentlicht 13.01.2026 22:51:48
- Zuletzt bearbeitet 21.01.2026 15:16:05
e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. ...
CVE-2025-11941
- EPSS 0.85%
- Veröffentlicht 19.10.2025 15:32:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing manipulation of the argument multiaction[] results in path tr...
CVE-2025-61505
- EPSS 0.33%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 12.01.2026 16:36:43
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers ...
CVE-2023-36121
- EPSS 1.19%
- Veröffentlicht 02.08.2023 00:15:18
- Zuletzt bearbeitet 21.11.2024 08:09:18
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
CVE-2021-27885
- EPSS 3.21%
- Veröffentlicht 02.03.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:41
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
CVE-2018-11734
- EPSS 0.78%
- Veröffentlicht 10.07.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 03:43:55
In e107 v2.1.7, output without filtering results in XSS.
CVE-2018-17423
- EPSS 0.74%
- Veröffentlicht 19.06.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 03:54:22
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVE-2016-10753
- EPSS 1.68%
- Veröffentlicht 24.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:40
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
CVE-2018-17081
- EPSS 0.59%
- Veröffentlicht 26.09.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:50
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.