PT-2026-43267 · E107 · E107

·

CVE-2026-43935

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions e107 versions prior to 2.3.4
Description e107 is a content management system (CMS). A Host Header Injection in the password reset page allows attackers to manipulate the Host header to generate password reset links that point to domains controlled by the attacker. This can lead to account takeover or phishing attacks.
Recommendations Update to version 2.3.4.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43935
GHSA-7PMW-JWVR-CQ2X

Affected Products

E107