Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

E107 HIGH 7.2
CVE-2022-50939

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro…

No fix yet
Fix from $1,950 2026-01-13
E107 HIGH 7.2
CVE-2022-50916

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manag…

No fix yet
Fix from $1,950 2026-01-13
E107 HIGH 7.2
CVE-2022-50907

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute …

No fix yet
Fix from $1,950 2026-01-13
E107 MEDIUM 6.1
CVE-2022-50905

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS th…

No fix yet
Fix from $1,600 2026-01-13
E107 HIGH 8.1
CVE-2025-11941

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of t…

Fix: after 2.3.3
Fix from $1,950 2025-10-19
E107 MEDIUM 6.5
CVE-2025-61505

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previo…

Fix: after 2.3.3
Fix from $1,600 2025-10-10
E107 Cms MEDIUM 5.4
CVE-2023-43873

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name fil…

No fix yet
Fix from $1,600 2023-09-28
E107 Cms MEDIUM 5.4
CVE-2023-43874

Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the C…

No fix yet
Fix from $1,600 2023-09-28
E107 MEDIUM 5.4
CVE-2023-36121

Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.

No fix yet
Fix from $1,600 2023-08-02
E107 HIGH 8.8
CVE-2021-27885

usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

Fix: after 2.3.0
Fix from $1,950 2021-03-02
E107 MEDIUM 6.1
CVE-2018-11734

In e107 v2.1.7, output without filtering results in XSS.

Mitigation only
Fix from $1,600 2019-07-10
E107 HIGH 8.8
CVE-2016-10753

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

No fix yet
Fix from $1,950 2019-05-24
E107 HIGH 7.2
CVE-2018-16388

e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg …

Patch available
Fix from $1,950 2018-09-12
E107 MEDIUM 6.5
CVE-2018-16389

e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.

Patch available
Fix from $1,600 2018-09-12
E107 MEDIUM 6.1
CVE-2018-16381

e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.

No fix yet
Fix from $1,600 2018-09-05
E107 HIGH 8.8
CVE-2018-15901

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

No fix yet
Fix from $1,950 2018-08-28
E107 MEDIUM 6.5
CVE-2018-11127

e107 2.1.7 has CSRF resulting in arbitrary user deletion.

Mitigation only
Fix from $1,600 2018-05-15
E107 HIGH 7.2
CVE-2016-10378

e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVis…

No fix yet
Fix from $1,950 2017-05-29
E107 MEDIUM 6.5
CVE-2017-8098

e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forge…

Patch available
Fix from $1,600 2017-04-24
E107 MEDIUM 6.8
CVE-2014-9459

Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote attackers to h…

Patch available
Fix from $1,600 2015-01-02
E107 MEDIUM 6.8
CVE-2012-6433

Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of admi…

Patch available
Fix from $1,600 2013-01-03
E107 MEDIUM 6.8
CVE-2012-6434

Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authenticati…

Patch available
Fix from $1,600 2013-01-03
E107 MEDIUM 6.8
CVE-2011-4946

SQL injection vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to execute arbitrary SQL commands via the …

Fix: after 0.7.24
Fix from $1,600 2012-08-31
E107 MEDIUM 6.8
CVE-2011-4947

Cross-site request forgery (CSRF) vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to hijack the authenti…

Fix: after 0.7.24
Fix from $1,600 2012-08-31
E107 MEDIUM 6.0
CVE-2010-5084

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the ad…

Fix: after 0.7.22
Fix from $1,600 2012-02-14
E107 MEDIUM 5.1
CVE-2011-4921

SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,600 2012-01-04
E107 HIGH 7.5
CVE-2011-1513EPSS 6%

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, al…

Fix: after 0.7.24
Fix from $1,950 2011-11-04
E107 MEDIUM 5.0
CVE-2011-3731

e107 0.7.24 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

No fix yet
Fix from $1,600 2011-09-23
E107 HIGH 7.5
CVE-2010-2098

Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks via the lo…

Fix: after 0.7.20
Fix from $1,950 2010-05-27
E107 HIGH 7.5
CVE-2010-2099

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows re…

Fix: after 0.7.20
Fix from $1,950 2010-05-27