📦

e107

Vendor: e107

Actively Exploited 0 CISA KEV List
PoC / Exploits 29 Code Available
Total RCEs 11 Remote Access
Total CVEs 1122 Total Indexed
Avg. EPSS 1.93% Exploit Prob.
Latest CVE CVE-2022-50939 Jan 13

Security Vulnerability Index

Page 2 / 113
4.8 CVSS

An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.

EPSS: 0.74%
8.8 CVSS

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

EPSS: 1.68%
4.3 CVSS

e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.

EPSS: 0.58%
6.5 CVSS

e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.

EPSS: 1.15%
7.2 CVSS

e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.

EPSS: 2.19%
6.1 CVSS

e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.

EPSS: 0.71%
8.8 CVSS

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

EPSS: 0.56%
6.5 CVSS

e107 2.1.7 has CSRF resulting in arbitrary user deletion.

EPSS: 0.53%
7.2 CVSS

e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.

EPSS: 1.26%
6.5 CVSS

e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.

EPSS: 0.66%