Browse all 6 CVE security advisories affecting e107inc. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57859 | e107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize() — e107CWE-502 | 7.5 | High | 2026-07-30 |
| CVE-2026-48997 | e107: Command Injection via shell expansion in ImageMagick resize destination path — e107CWE-78 | 7.1 | High | 2026-06-17 |
| CVE-2026-46620 | e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check() — e107CWE-285 | 6.5 | Medium | 2026-05-26 |
| CVE-2026-43935 | e107: Host Header Injection in e107 password reset enables phishing — e107CWE-20 | 8.1 | High | 2026-05-26 |
| CVE-2026-43934 | e107: Broken Access Control in e107 comment edit allows cross-user comment modification — e107CWE-284 | 6.5 | Medium | 2026-05-26 |
| CVE-2026-43936 | e107: Server-Side Request Forgery (SSRF) in the remote file fetcher — e107CWE-918 | 4.3 | Medium | 2026-05-26 |
This page lists every published CVE security advisory associated with e107inc. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.