Перейти к содержимому
Noroxi

Записи eyoucms

75 опубликованных записей вендора eyoucms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
1,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

75 записей
  • CVE-2020-24000
    40В плане

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    eyoucms · eyoucms3 нояб. 2021 г.

  • CVE-2021-39497
    40В плане

    eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    eyoucms · eyoucms7 сент. 2021 г.

  • CVE-2022-26279
    40В плане

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    eyoucms · eyoucms24 мар. 2022 г.

  • CVE-2022-26273
    39Наблюдать

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms27 мар. 2022 г.

  • CVE-2023-42286
    39Наблюдать

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms14 мар. 2024 г.

  • CVE-2024-3431
    35Наблюдать

    EyouCMS Backend deserialization

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms7 апр. 2024 г.

  • CVE-2020-19669
    35Наблюдать

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms18 авг. 2021 г.

  • CVE-2020-18129
    35Наблюдать

    A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms22 окт. 2020 г.

  • CVE-2020-20642
    35Наблюдать

    Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eyoucms · eyoucms19 авг. 2021 г.

  • CVE-2022-36225
    35Наблюдать

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    eyoucms · eyoucms19 авг. 2022 г.

  • CVE-2022-41500
    35Наблюдать

    EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    eyoucms · eyoucms18 окт. 2022 г.

  • CVE-2022-43323
    35Наблюдать

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    eyoucms · eyoucms14 нояб. 2022 г.

  • CVE-2022-44387
    35Наблюдать

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    eyoucms · eyoucms14 нояб. 2022 г.

  • CVE-2021-46255
    32Наблюдать

    eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    eyoucms · eyoucms13 янв. 2022 г.

  • CVE-2021-39500
    30Наблюдать

    Eyoucms 1.5.4 is vulnerable to Directory Traversal.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    eyoucms · eyoucms7 сент. 2021 г.

  • CVE-2024-48196
    30Наблюдать

    An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    eyoucms · eyoucms28 окт. 2024 г.

  • CVE-2025-65868
    30Наблюдать

    XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    eyoucms · eyoucms3 дек. 2025 г.

  • CVE-2023-37645
    28Наблюдать

    eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

    СредняяCVSS 5,3Proof of conceptEPSS 25 %

    eyoucms · eyoucms20 июл. 2023 г.

  • CVE-2021-42194
    28Наблюдать

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    eyoucms · eyoucms20 мар. 2022 г.

  • CVE-2022-44389
    26Наблюдать

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    eyoucms · eyoucms14 нояб. 2022 г.

  • CVE-2021-39501
    25Наблюдать

    EyouCMS 1.5.4 is vulnerable to Open Redirect.

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    eyoucms · eyoucms7 сент. 2021 г.

  • CVE-2020-28146
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eyoucms · eyoucms18 авг. 2021 г.

  • CVE-2023-41597
    24Наблюдать

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    eyoucms · eyoucms15 нояб. 2023 г.

  • CVE-2021-39499
    24Наблюдать

    A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eyoucms · eyoucms7 сент. 2021 г.

  • CVE-2024-22927
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    eyoucms · eyoucms1 февр. 2024 г.