VYPR

Vendor CVEs

Eyoucms

All CVEs

79 total · sorted by risk
  • CVE-2023-42286CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.

  • CVE-2022-26273CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

  • CVE-2022-26279CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

  • CVE-2020-24000CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

  • CVE-2021-39497CriSep 7, 2021
    risk 0.64cvss 9.8epss 0.02

    eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

  • CVE-2022-44387HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.

  • CVE-2022-43323HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

  • CVE-2022-41500HigOct 18, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.

  • CVE-2022-36225HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

  • CVE-2020-20642HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.

  • CVE-2020-19669HigAug 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.

  • CVE-2020-18129HigOct 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

  • CVE-2021-46255HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

  • CVE-2025-65868HigDec 3, 2025
    risk 0.49cvss 7.5epss 0.00

    XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

  • CVE-2024-48196HigOct 28, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

  • CVE-2021-39500HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.

  • CVE-2026-7389HigApr 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2021-42194HigMar 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

  • CVE-2022-44389MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.

  • CVE-2026-1107MedJan 18, 2026
    risk 0.41cvss 6.3epss 0.01

    A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload. The attack may be performed from…

  • CVE-2025-15375MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be…

  • CVE-2025-15373MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-52335MedAug 14, 2025
    risk 0.40cvss 6.1epss 0.00

    EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

  • CVE-2024-52680MedAug 7, 2025
    risk 0.40cvss 6.1epss 0.00

    EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

  • CVE-2024-48195MedOct 28, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

  • CVE-2024-23034MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23033MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23032MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-23031MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2024-22927MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

  • CVE-2023-41597MedNov 15, 2023
    risk 0.40cvss 6.1epss 0.01

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

  • CVE-2023-30125MedApr 28, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-45541MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.

  • CVE-2022-45540MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.

  • CVE-2022-45539MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.

  • CVE-2022-45538MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".

  • CVE-2022-45537MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".

  • CVE-2021-39501MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.04

    EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

  • CVE-2021-39499MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.

  • CVE-2020-28146MedAug 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

  • CVE-2019-17430MedOct 10, 2019
    risk 0.40cvss 6.1epss 0.01

    EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.

  • CVE-2023-37645MedJul 20, 2023
    risk 0.36cvss 5.3epss 0.25

    eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

  • CVE-2024-11210MedNov 14, 2024
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely.…

  • CVE-2023-50566MedDec 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter.

  • CVE-2023-46935MedNov 21, 2023
    risk 0.35cvss 5.4epss 0.00

    eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

  • CVE-2023-37136MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37135MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37134MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37133MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37132MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Page 1 of 2