CVE Tools

E107

84 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for E107, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

E107 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
E107 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-102
2025-110
2025-120
2026-015
2026-020
2026-030
2026-040
2026-054
2026-061
2026-071
2026-081
2026-090

Severity

How the 84 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical34%
  • High2530%
  • Medium5565%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting E107.

  1. CVE-2026-72599e107 e107 - SQL Injection9.8
  2. CVE-2026-57859e107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize()7.5
  3. CVE-2026-48997e107: Command Injection via shell expansion in ImageMagick resize destination path7.1
  4. CVE-2026-46620e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()6.5
  5. CVE-2026-43935e107: Host Header Injection in e107 password reset enables phishing8.1
  6. CVE-2026-43934e107: Broken Access Control in e107 comment edit allows cross-user comment modification6.5
  7. CVE-2026-43936e107: Server-Side Request Forgery (SSRF) in the remote file fetcher4.3
  8. CVE-2022-50939e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override7.2
  9. CVE-2022-50916e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override7.2
  10. CVE-2022-50907e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE7.2
  11. CVE-2022-50906e107 CMS v3.2.1 - Admin Upload Restriction Bypass + Stored XSS4.8
  12. CVE-2022-50905e107 CMS v3.2.1 - Reflected XSS via Comment Flow9.8
  13. CVE-2025-11941e107 CMS Avatar image.php path traversal5.4
  14. CVE-2025-61505e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base...6.5
  15. CVE-2023-36121Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store