CVE-2026-72599: e107
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.
Affected products
- e107 e107: up to and including 2.4.0
Published 2026-08-11. Last modified 2026-09-03.