CVE-2026-48997 | e107 up to 2.3.5 Setting resize_image os command injection (GHSA-3j33-c9v4-4p42)
A vulnerability was found in e107 up to 2.3.5. It has been rated as critical. Affected by this vulnerability is the function resize_image of the component Setting Handler. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-48997. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More