CVE-2026-43935HIGH 8.1EPSS p21.2%

CVE-2026-43935CVE-2026-43935

Description

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or other security risks. The severity is high, as the vulnerability affects a critical function related to user authentication. This vulnerability is fixed in 2.3.4.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS0.30% probability of exploitation · percentile 21.2% · 2026-06-19T12:03:05Z
Published2026-05-26
Last modified2026-05-26

Underlying weaknesses· 2

CWE-20CWE-807

References

  1. https://github.com/e107inc/e107/commit/04511f9f1d6e97c31ba7cc5bf7f1f9a19d221db6
  2. https://github.com/e107inc/e107/commit/b0dee8234e273debbf7a8ae054de464f1008f357
  3. https://github.com/e107inc/e107/commit/c4f9f71b0fd695545d0f09e2277b6f70ff4660fc
  4. https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x
  5. https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x

2

TypeTargetConfidenceTier
WeaknessImproper Input Validationcwe-200%live
WeaknessReliance on Untrusted Inputs in a Security Decisioncwe-8070%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-26747
CVE
CVE-2026-29199
CVE
CVE-2026-39110
CVE
CVE-2025-43931
CVE
CVE-2025-11941
CVE
CVE-2026-29067
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.