Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

e107 — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting e107. AI-powered Chinese analysis, POCs, and references for each vulnerability.

e107 is an open-source content management system designed for building websites and online communities. Historically, it has been susceptible to various vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with six CVEs currently documented. The platform's modular architecture and extensive plugin ecosystem have introduced security challenges, often stemming from insufficient input validation and access controls. While no major public security incidents have been widely reported, the consistent presence of vulnerabilities in older versions highlights the importance of regular updates and proper hardening for production deployments.

Found 1 results / 8Clear Filters
Top products by e107: e107 CMS CMS e107
HighCVE-2026-57592026-07-30
Second-order code execution via eval()-based deserialization in e107::unserialize() · Advisory · e107inc/e107 · GitHub
Unknown2026-07-30
fix(events): skip notify handlers whose class no longer exists · e107inc/e107@40e73ce · GitHub
High2026-07-30
GitHub - e107inc/e107: e107 Bootstrap CMS (Content Management System) v2 with PHP, MySQL, HTML5, jQuery and Twitter Boot
High2026-06-18
Command Injection via ImageMagick resize destination path is shell-expanded · Advisory · e107inc/e107 · GitHub
Medium2026-05-27
fix(fpw): Refuse password reset when `siteurl` pref is empty · e107inc/e107@04511f9 · GitHub
High2026-05-27
fix(file): Canonicalize IPv4-mapped IPv6 before SSRF range check · e107inc/e107@40b2d11 · GitHub
High2026-05-27
fix(comment): Restrict comment edits to the comment's author · e107inc/e107@23961a8 · GitHub
High2026-05-27
Host Header Injection in e107 password reset enables phishing · Advisory · e107inc/e107 · GitHub
MediumCVE-2025-49362026-05-27
Server-Side Request Forgery (SSRF) in e107 remote file fetcher · Advisory · e107inc/e107 · GitHub
MediumCVE-2026-439342026-05-27
Broken Access Control in e107 comment edit allows cross-user comment modification · Advisory · e107inc/e107 · GitHub
Low2026-05-27
Issue #5458 Make sure configured siteurl preference contains 'http'. · e107inc/e107@b0dee82 · GitHub
High2026-05-27
fix(file): Block SSRF via private IPs in remote file fetching · e107inc/e107@5f98cc9 · GitHub
Low2026-05-27
Issue #5458 - support subdomains · e107inc/e107@c4f9f71 · GitHub
MediumCVE-2026-46202026-05-27
CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check() · Advisory · e107inc/

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with e107. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.