Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
E107:
>> E107
Security Vulnerabilities
CVE-2023-36121
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
CVSS Score
5.4
EPSS Score
0.009
Published
2023-08-02
CVE-2021-27885
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
CVSS Score
8.8
EPSS Score
0.003
Published
2021-03-02
CVE-2018-11734
In e107 v2.1.7, output without filtering results in XSS.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-10
CVE-2018-17423
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-06-19
CVE-2016-10753
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-05-24
CVE-2018-17081
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
CVSS Score
4.3
EPSS Score
0.002
Published
2018-09-26
CVE-2018-16388
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
CVSS Score
7.2
EPSS Score
0.008
Published
2018-09-12
CVE-2018-16389
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-09-12
CVE-2018-16381
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-09-05
CVE-2018-15901
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-08-28
Next
Page 1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved