Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

E107 HIGH 7.2
CVE-2022-50939

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro…

No fix yet
Fix from $1,950 2026-01-13
E107 HIGH 7.2
CVE-2022-50916

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manag…

No fix yet
Fix from $1,950 2026-01-13
E107 HIGH 7.2
CVE-2022-50907

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute …

No fix yet
Fix from $1,950 2026-01-13
E107 MEDIUM 6.1
CVE-2022-50905

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS th…

No fix yet
Fix from $1,600 2026-01-13
E107 Cms MEDIUM 5.4
CVE-2023-43873

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name fil…

No fix yet
Fix from $1,600 2023-09-28
E107 Cms MEDIUM 5.4
CVE-2023-43874

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the C…

No fix yet
Fix from $1,600 2023-09-28
E107 MEDIUM 5.4
CVE-2023-36121

Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.

No fix yet
Fix from $1,600 2023-08-02
E107 MEDIUM 6.1
CVE-2018-11734

In e107 v2.1.7, output without filtering results in XSS.

Mitigation only
Fix from $1,600 2019-07-10
E107 HIGH 8.8
CVE-2016-10753

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

No fix yet
Fix from $1,950 2019-05-24
E107 MEDIUM 6.1
CVE-2018-16381

e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.

No fix yet
Fix from $1,600 2018-09-05
E107 HIGH 8.8
CVE-2018-15901

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

No fix yet
Fix from $1,950 2018-08-28
E107 MEDIUM 6.5
CVE-2018-11127

e107 2.1.7 has CSRF resulting in arbitrary user deletion.

Mitigation only
Fix from $1,600 2018-05-15
E107 HIGH 7.2
CVE-2016-10378

e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVis…

No fix yet
Fix from $1,950 2017-05-29
E107 MEDIUM 5.1
CVE-2011-4921

SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,600 2012-01-04
E107 MEDIUM 5.0
CVE-2011-3731

e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

No fix yet
Fix from $1,600 2011-09-23
E107 MEDIUM 5.1
CVE-2009-1409

SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, …

No fix yet
Fix from $1,600 2009-04-24
Alternate Profiles Plugin HIGH 7.5
CVE-2008-4785

SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL …

No fix yet
Fix from $1,950 2008-10-29
Easyshop Plugin HIGH 7.5
CVE-2008-4786

SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the categor…

No fix yet
Fix from $1,950 2008-10-29
E107 HIGH 7.5
CVE-2008-2020

The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitT…

Mitigation only
Fix from $1,950 2008-04-30
E107 MEDIUM 6.8
CVE-2007-3429

Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload …

No fix yet
Fix from $1,600 2007-06-27
E107 HIGH 7.5
CVE-2006-5786

Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via…

No fix yet
Fix from $1,950 2006-11-07
E107 HIGH 7.5
CVE-2006-4548

e107 0.75 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame…

No fix yet
Fix from $1,950 2006-09-06
E107 HIGH 7.5
CVE-2005-4224

Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hide…

Mitigation only
Fix from $1,950 2005-12-14
E107 MEDIUM 5.0
CVE-2005-4051

e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.

No fix yet
Fix from $1,600 2005-12-07
E107 MEDIUM 5.0
CVE-2005-3594

game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name …

Mitigation only
Fix from $1,600 2005-11-16
E107 MEDIUM 5.0
CVE-2005-2805

forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.

Mitigation only
Fix from $1,600 2005-09-06
E107 HIGH 7.5
CVE-2005-1949

The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell me…

Mitigation only
Fix from $1,950 2005-06-16
E107 HIGH 7.5
CVE-2005-1966

The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a…

Mitigation only
Fix from $1,950 2005-06-10