← Back

E107

e107

Vendor: E107 • 77 CVEs

CVEs (77)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1E107
1E107
Jun 17, 2026
Jan 13, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's rem...Show more
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (image.php) where the upload_caption parameter is not properly sanitized. An attacker with administrative privileges can use directory traversal sequences (../../../) in the upload_caption field to overwrite critical system files outside the intended upload directory. This can lead to complete compromise of the web application by overwriting configuration files, executable scripts, or other critical system components. The vulnerability was discovered by Hubert Wojciechowski and affects the image.php component in the admin interface.Show less
1E107
1E107
Jun 17, 2026
Jan 13, 2026
8.7 HIGH· v4
7.2 HIGH· v3
N/A· v2
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by...Show more
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.Show less
1E107
1E107
Jun 17, 2026
Jan 13, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directori...Show more
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.Show less
1E107
1E107
Jun 17, 2026
Jan 13, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulner...Show more
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.Show less
1E107
1E107
Jun 17, 2026
Jan 13, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users in...Show more
e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. An attacker can inject malicious JavaScript code through the URL parameter that gets executed when users click outside the comment field after typing content. The second vulnerability involves an upload restriction bypass for authenticated administrators, allowing them to upload SVG files containing malicious code through the media manager's remote URL upload feature. This results in stored XSS when the uploaded SVG files are accessed. These vulnerabilities were discovered by Hubert Wojciechowski and affect the news.php and image.php components of the CMS.Show less
1E107
1E107
Jun 17, 2026
Oct 19, 2025
2.1 LOW· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing manipulation of the argument mu...Show more
A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing manipulation of the argument multiaction[] results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1E107
1E107
Jun 17, 2026
Oct 10, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without v...Show more
e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could lead to remote code execution, arbitrary file operations, or denial of service, depending on available PHP object gadgets in the codebase.Show less
1E107
1E107
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
1E107
1E107
Jun 17, 2026
Mar 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
1E107
1E107
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In e107 v2.1.7, output without filtering results in XSS.
1E107
1E107
Nov 21, 2024
Jun 19, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
1E107
1E107
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
1E107
1E107
Nov 21, 2024
Sep 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
1E107
1E107
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
1E107
1E107
Nov 21, 2024
Sep 12, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
1E107
1E107
Nov 21, 2024
Sep 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
1E107
1E107
Nov 21, 2024
Aug 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
1E107
1E107
Nov 21, 2024
May 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
1E107
1E107
May 13, 2026
May 29, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
1E107
1E107
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the...Show more
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.Show less