CVE-2011-4921: e107

Medium severity, CVSS 5.1. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.

Affected products

  • e107 e107: version 0.7.26 only

Published 2012-01-04. Last modified 2026-06-16.