CVE-2016-10753: e107

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

Affected products

  • e107 e107: version 2.1.2 only

Published 2019-05-24. Last modified 2026-06-17.