VYPR

Eyoucms

by Eyoucms

Source repositories

CVEs (79)

  • CVE-2025-15375MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be…

  • CVE-2025-15373MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-52335MedAug 14, 2025
    risk 0.40cvss 6.1epss 0.00

    EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

  • CVE-2024-52680MedAug 7, 2025
    risk 0.40cvss 6.1epss 0.00

    EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

  • CVE-2024-48195MedOct 28, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

  • CVE-2024-23034MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23033MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23032MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23031MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-22927MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2023-41597MedNov 15, 2023
    risk 0.40cvss 6.1epss 0.01

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

  • CVE-2023-30125MedApr 28, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-45541MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.

  • CVE-2022-45540MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.

  • CVE-2022-45539MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.

  • CVE-2022-45538MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".

  • CVE-2022-45537MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".

  • CVE-2021-39501MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.04

    EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

  • CVE-2021-39499MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.

  • CVE-2020-28146MedAug 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.