AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-0681

CRITICAL · CVSS 9.8 EPSS 5.04% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-02-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2007-0681
Severity
CRITICAL
CVSS
9.8
EPSS
5.04%

Original Filing — NVD Description

profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.