VYPR
High severity8.8NVD Advisory· Published May 10, 2026· Updated May 12, 2026

CVE-2021-47937

CVE-2021-47937

Description

e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script.

Affected products

2
  • E107/E107inferred2 versions
    =2.3.0+ 1 more
    • (no CPE)range: =2.3.0
    • (no CPE)range: = 2.3.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.