CVE-2026-72599
e107 e107 - SQL Injection
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.
| CWE | CWE-89 |
| Vendor | e107 |
| Product | e107 |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for e107 e107
Be the first to know when new critical vulnerabilities affecting e107 e107 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
e107 / e107
0 โค 2.4.0
Credits
Bobur Abdugafforov