e107 versions 0.7.16 and below suffer from cross site scripting and SQL injection vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82876/Bkis-13-2009.txt
Source: https://packetstormsecurity.com/files/82876/e107-SQL-Injection-Cross-Site-Scripting.html

