Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

E107

First CVE: Oct 29, 2003Active for: 23 yearsTotal CVEs: 91
37.8
VTI Score
Medium

E107 is a content management system and plugin ecosystem with a narrow product footprint but significant adoption in web hosting and small-business website deployments. Its vulnerability profile is dominated by web-application flaws—principally cross-site scripting, SQL injection, cross-site request forgery, and unrestricted file uploads—that recur across the core platform and extensions such as the ChatBox, EasyShop, and Alternate Profiles plugins, reflecting the input-handling and file-management demands typical of PHP-based CMS architectures. Public exploit code frequently becomes available for this vendor's disclosures, consistent with the straightforward nature of web-application vulnerabilities and the accessibility of its open-source codebase to security researchers and attackers alike. Defenders should maintain close attention to this vendor's patch cycles and treat deployed instances as vectors for both direct compromise and lateral movement in shared hosting environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
91
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by E107 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 29, 2003
22 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (91 CVEs).

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27885HIGH
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
Mar 2, 20218.838NOYES
CVE-2008-1989HIGH
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitr
Apr 27, 200810.036NOYES
CVE-2004-2262HIGH
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the uploa
Dec 31, 20047.535NOYES
CVE-2010-2099HIGH
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbit
May 27, 20107.534NOYES
CVE-2011-1513HIGH
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject
Nov 4, 20117.533NOYES
CVE-2012-6434MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for reques
Jan 3, 20136.832NOYES
CVE-2012-6433MEDIUM
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that co
Jan 3, 20136.831NOYES
CVE-2008-6438HIGH
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid
Mar 6, 20097.529NOYES
CVE-2016-10753HIGH
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
May 24, 20198.828NONO
CVE-2008-6466HIGH
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL command
Mar 13, 20097.528NOYES
View all 91 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products91 CVEs
65%
34%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network23 (25.3%)
Unknown68 (74.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (25.3%)
High0 (0.0%)
Unknown68 (74.7%)
User Interaction
None10 (11.0%)
Unknown68 (74.7%)
Required13 (14.3%)
Privileges Required
Low5 (5.5%)
High8 (8.8%)
None10 (11.0%)
Unknown68 (74.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
31.9% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by E107.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by E107 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For E107's Products

View all 5 CNAs →

Top CWEs