Filtered by vendor E107
Subscriptions
Total
84 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-16389 | 1 E107 | 1 E107 | 2024-08-05 | N/A |
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter. | ||||
CVE-2018-15901 | 1 E107 | 1 E107 | 2024-08-05 | N/A |
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators. | ||||
CVE-2018-11734 | 1 E107 | 1 E107 | 2024-08-05 | N/A |
In e107 v2.1.7, output without filtering results in XSS. | ||||
CVE-2021-27885 | 1 E107 | 1 E107 | 2024-08-03 | 8.8 High |
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. |