E107 is a content management system and plugin ecosystem with a narrow product footprint but significant adoption in web hosting and small-business website deployments. Its vulnerability profile is dominated by web-application flaws—principally cross-site scripting, SQL injection, cross-site request forgery, and unrestricted file uploads—that recur across the core platform and extensions such as the ChatBox, EasyShop, and Alternate Profiles plugins, reflecting the input-handling and file-management demands typical of PHP-based CMS architectures. Public exploit code frequently becomes available for this vendor's disclosures, consistent with the straightforward nature of web-application vulnerabilities and the accessibility of its open-source codebase to security researchers and attackers alike. Defenders should maintain close attention to this vendor's patch cycles and treat deployed instances as vectors for both direct compromise and lateral movement in shared hosting environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E107 over time
Signals from CVEs in this vendor scope (91 CVEs).
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27885HIGH usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. | Mar 2, 2021 | 8.8 | 38 | NO | YES |
CVE-2008-1989HIGH PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitr | Apr 27, 2008 | 10.0 | 36 | NO | YES |
CVE-2004-2262HIGH ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the uploa | Dec 31, 2004 | 7.5 | 35 | NO | YES |
CVE-2010-2099HIGH bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbit | May 27, 2010 | 7.5 | 34 | NO | YES |
CVE-2011-1513HIGH Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject | Nov 4, 2011 | 7.5 | 33 | NO | YES |
CVE-2012-6434MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for reques | Jan 3, 2013 | 6.8 | 32 | NO | YES |
CVE-2012-6433MEDIUM Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that co | Jan 3, 2013 | 6.8 | 31 | NO | YES |
CVE-2008-6438HIGH SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid | Mar 6, 2009 | 7.5 | 29 | NO | YES |
CVE-2016-10753HIGH e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC. | May 24, 2019 | 8.8 | 28 | NO | NO |
CVE-2008-6466HIGH SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL command | Mar 13, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (91 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E107.
Media articles that mention a CVE ID that affects a product developed by E107 — matched by CVE ID, not by vendor name.