Eyoucms
by Eyoucms
Source repositories
CVEs (79)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15375 | Med | 0.41 | 6.3 | 0.00 | Dec 31, 2025 | A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be… | ||
| CVE-2025-15373 | Med | 0.41 | 6.3 | 0.00 | Dec 31, 2025 | A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed… | ||
| CVE-2025-52335 | Med | 0.40 | 6.1 | 0.00 | Aug 14, 2025 | EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information. | ||
| CVE-2024-52680 | Med | 0.40 | 6.1 | 0.00 | Aug 7, 2025 | EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. | ||
| CVE-2024-48195 | Med | 0.40 | 6.1 | 0.00 | Oct 28, 2024 | Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. | ||
| CVE-2024-23034 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2024 | Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | ||
| CVE-2024-23033 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2024 | Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | ||
| CVE-2024-23032 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2024 | Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | ||
| CVE-2024-23031 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | ||
| CVE-2024-22927 | Med | 0.40 | 6.1 | 0.01 | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | ||
| CVE-2023-41597 | Med | 0.40 | 6.1 | 0.01 | Nov 15, 2023 | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. | ||
| CVE-2023-30125 | Med | 0.40 | 6.1 | 0.00 | Apr 28, 2023 | EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2022-45541 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char. | ||
| CVE-2022-45540 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char. | ||
| CVE-2022-45539 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file. | ||
| CVE-2022-45538 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL". | ||
| CVE-2022-45537 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL". | ||
| CVE-2021-39501 | Med | 0.40 | 6.1 | 0.04 | Sep 7, 2021 | EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function. | ||
| CVE-2021-39499 | Med | 0.40 | 6.1 | 0.01 | Sep 7, 2021 | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function. | ||
| CVE-2020-28146 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2021 | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. |
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be…
- risk 0.41cvss 6.3epss 0.00
A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…
- risk 0.40cvss 6.1epss 0.00
EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.
- risk 0.40cvss 6.1epss 0.00
EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- risk 0.40cvss 6.1epss 0.01
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
- risk 0.40cvss 6.1epss 0.00
EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.
- risk 0.40cvss 6.1epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.
- risk 0.40cvss 6.1epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.
- risk 0.40cvss 6.1epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
- risk 0.40cvss 6.1epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
- risk 0.40cvss 6.1epss 0.04
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
- risk 0.40cvss 6.1epss 0.01
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
Page 2 of 4