CVE-2026-48997
e107inc e107
e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path is inserted inside raw double quotes in the convert command; in the submit-news upload flow, that destination filename includes the first six characters of user-controlled news title input. Because the title filter removes literal spaces but not tab characters, and shell expansions such as $(...) and backticks can survive into the quoted destina...
- CVSS
- 7.1
- EPSS
- 0.75% 51.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18