VYPR

Eyoucms

by Eyoucms

Source repositories

CVEs (79)

  • CVE-2023-42286CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.

  • CVE-2022-26273CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

  • CVE-2022-26279CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

  • CVE-2020-24000CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

  • CVE-2021-39497CriSep 7, 2021
    risk 0.64cvss 9.8epss 0.02

    eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

  • CVE-2022-44387HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.

  • CVE-2022-43323HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

  • CVE-2022-41500HigOct 18, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.

  • CVE-2022-36225HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

  • CVE-2020-20642HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.

  • CVE-2020-19669HigAug 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.

  • CVE-2020-18129HigOct 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

  • CVE-2021-46255HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

  • CVE-2025-65868HigDec 3, 2025
    risk 0.49cvss 7.5epss 0.00

    XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

  • CVE-2024-48196HigOct 28, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

  • CVE-2021-39500HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.

  • CVE-2026-7389HigApr 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2021-42194HigMar 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

  • CVE-2022-44389MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.

  • CVE-2026-1107MedJan 18, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload. The attack may be performed from…

Page 1 of 4