Technology · E107inc
E107inc E107 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 8 vulnerabilities in E107inc E107: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-72599, was published on 11 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
About E107inc E107
e107 is an open-source content management system written in PHP and using a MySQL database.
Latest E107inc E107 vulnerabilities
- CVE-2026-72599: e107 SQL injection in news item page ID parametercriticalCVSS 9.8EPSS 0.6%
- CVE-2026-57859: e107 CMS remote code execution in e_array deserializationhighCVSS 7.5
- CVE-2026-48997: e107 CMS command injection in ImageMagick resize destination pathhighCVSS 7.1EPSS 0.8%
- CVE-2026-46620: e107 CMS CSRF in comment moderation endpointsmediumCVSS 6.5
- CVE-2026-43936: e107 SSRF in Media Manager remote file fetchermediumCVSS 4.3
- CVE-2026-43935: e107 CMS Host Header Injection in password reset pagehighCVSS 8.1
- CVE-2026-43934: e107 CMS broken access control in comment editingmediumCVSS 6.5
- CVE-2021-47937: e107 CMS remote code execution via theme uploadhighCVSS 8.8EPSS 0.6%
Most severe E107inc E107 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-72599: e107 SQL injection in news item page ID parametercriticalCVSS 9.8EPSS 0.6%
- CVE-2021-47937: e107 CMS remote code execution via theme uploadhighCVSS 8.8EPSS 0.6%
- CVE-2026-43935: e107 CMS Host Header Injection in password reset pagehighCVSS 8.1
- CVE-2026-57859: e107 CMS remote code execution in e_array deserializationhighCVSS 7.5
- CVE-2026-48997: e107 CMS command injection in ImageMagick resize destination pathhighCVSS 7.1EPSS 0.8%
- CVE-2026-46620: e107 CMS CSRF in comment moderation endpointsmediumCVSS 6.5
- CVE-2026-43934: e107 CMS broken access control in comment editingmediumCVSS 6.5
- CVE-2026-43936: e107 SSRF in Media Manager remote file fetchermediumCVSS 4.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/e107.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "E107inc E107 vulnerabilities", https://junglewise.ai/threats/technologies/e107, 26 September 2026.