SQL Injection Vulnerability in e107 Product by e107inc
CVE-2026-72599

9.8CRITICAL

Key Information:

Vendor

E107

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72599?

An SQL injection flaw in e107 version 2.4.0 permits remote attackers, without authentication, to execute arbitrary SQL commands through the news item page ID parameter. This vulnerability arises from improper input handling, where user-supplied data is concatenated into an SQL WHERE clause without adequate escaping. An attacker can leverage this vulnerability to manipulate database queries, enabling unauthorized access to read, alter, or delete data, including sensitive information like administrator credentials.

Affected Version(s)

e107 0 <= 2.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.