VYPR

Eyoucms

by Eyoucms

Source repositories

CVEs (79)

  • CVE-2019-17430MedOct 10, 2019
    risk 0.40cvss 6.1epss 0.01

    EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.

  • CVE-2023-37645MedJul 20, 2023
    risk 0.36cvss 5.3epss 0.25

    eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

  • CVE-2024-11210MedNov 14, 2024
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely.…

  • CVE-2023-50566MedDec 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter.

  • CVE-2023-46935MedNov 21, 2023
    risk 0.35cvss 5.4epss 0.00

    eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

  • CVE-2023-37136MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37135MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37134MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37133MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37132MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-36093MedJun 22, 2023
    risk 0.35cvss 5.4epss 0.00

    There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3

  • CVE-2023-33492MedJun 12, 2023
    risk 0.35cvss 5.4epss 0.00

    EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-45755MedFeb 8, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page.

  • CVE-2022-45542MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.

  • CVE-2021-39428MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.

  • CVE-2022-45280MedNov 23, 2022
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-44390MedNov 14, 2022
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field.

  • CVE-2022-35509MedAug 10, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive…

  • CVE-2021-39496MedSep 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.

  • CVE-2020-20645MedAug 19, 2021
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.