Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2022-50939
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro…
E107
No fix yet
HIGH 7.2
CVE-2022-50916
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manag…
E107
No fix yet
HIGH 7.2
CVE-2022-50907
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute …
E107
No fix yet
MEDIUM 6.1
CVE-2022-50905
e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS th…
E107
No fix yet
MEDIUM 5.4
CVE-2023-43873
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name fil…
E107 Cms
No fix yet
MEDIUM 5.4
CVE-2023-43874
Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the C…
E107 Cms
No fix yet
MEDIUM 5.4
CVE-2023-36121
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
E107
No fix yet
MEDIUM 6.1
CVE-2018-11734
In e107 v2.1.7, output without filtering results in XSS.
E107
Mitigation only
HIGH 8.8
CVE-2016-10753
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
E107
No fix yet
MEDIUM 6.1
CVE-2018-16381
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
E107
No fix yet
HIGH 8.8
CVE-2018-15901
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
E107
No fix yet
MEDIUM 6.5
CVE-2018-11127
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
E107
Mitigation only
HIGH 7.2
CVE-2016-10378
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVis…
E107
No fix yet
MEDIUM 5.1
CVE-2011-4921
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrar…
E107
Mitigation only
MEDIUM 5.0
CVE-2011-3731
e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…
E107
No fix yet
MEDIUM 5.1
CVE-2009-1409
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, …
E107
No fix yet
HIGH 7.5
CVE-2008-4785
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL …
Alternate Profiles Plugin
No fix yet
HIGH 7.5
CVE-2008-4786
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the categor…
Easyshop Plugin
No fix yet
HIGH 7.5
CVE-2008-2020
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitT…
E107
Mitigation only
MEDIUM 6.8
CVE-2007-3429
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload …
E107
No fix yet
HIGH 7.5
CVE-2006-5786
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via…
E107
No fix yet
HIGH 7.5
CVE-2006-4548
e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame…
E107
No fix yet
HIGH 7.5
CVE-2005-4224
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hide…
E107
Mitigation only
MEDIUM 5.0
CVE-2005-4051
e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.
E107
No fix yet
MEDIUM 5.0
CVE-2005-3594
game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name …
E107
Mitigation only
MEDIUM 5.0
CVE-2005-2805
forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.
E107
Mitigation only
HIGH 7.5
CVE-2005-1949
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell me…
E107
Mitigation only
HIGH 7.5
CVE-2005-1966
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a…
E107
Mitigation only