Eyoucms
by Eyoucms
Source repositories
CVEs (79)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17430 | Med | 0.40 | 6.1 | 0.01 | Oct 10, 2019 | EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter. | ||
| CVE-2023-37645 | Med | 0.36 | 5.3 | 0.25 | Jul 20, 2023 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | ||
| CVE-2024-11210 | Med | 0.35 | 5.4 | 0.01 | Nov 14, 2024 | A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely.… | ||
| CVE-2023-50566 | Med | 0.35 | 5.4 | 0.00 | Dec 14, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter. | ||
| CVE-2023-46935 | Med | 0.35 | 5.4 | 0.00 | Nov 21, 2023 | eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users. | ||
| CVE-2023-37136 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37135 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37134 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37133 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37132 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-36093 | Med | 0.35 | 5.4 | 0.00 | Jun 22, 2023 | There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3 | ||
| CVE-2023-33492 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2023 | EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2022-45755 | Med | 0.35 | 5.4 | 0.00 | Feb 8, 2023 | Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page. | ||
| CVE-2022-45542 | Med | 0.35 | 5.4 | 0.00 | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file. | ||
| CVE-2021-39428 | Med | 0.35 | 5.4 | 0.01 | Dec 15, 2022 | Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic. | ||
| CVE-2022-45280 | Med | 0.35 | 5.4 | 0.00 | Nov 23, 2022 | A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2022-44390 | Med | 0.35 | 5.4 | 0.00 | Nov 14, 2022 | A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field. | ||
| CVE-2022-35509 | Med | 0.35 | 5.4 | 0.01 | Aug 10, 2022 | An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive… | ||
| CVE-2021-39496 | Med | 0.35 | 5.4 | 0.01 | Sep 7, 2021 | Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS. | ||
| CVE-2020-20645 | Med | 0.35 | 5.4 | 0.00 | Aug 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area. |
- risk 0.40cvss 6.1epss 0.01
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
- risk 0.36cvss 5.3epss 0.25
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely.…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter.
- risk 0.35cvss 5.4epss 0.00
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3
- risk 0.35cvss 5.4epss 0.00
EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page.
- risk 0.35cvss 5.4epss 0.00
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive…
- risk 0.35cvss 5.4epss 0.01
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
Page 3 of 4