eyoucms records
75 published records for vendor eyoucms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 1.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')47
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
75 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-24000No exploit | SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tieyoucms · eyoucms · CWE-89 | Critical9.8 | — | 2.4% | Nov 3, 2021 |
40Plan | CVE-2021-39497No exploit | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.eyoucms · eyoucms · CWE-918 | Critical9.8 | — | 2.4% | Sep 7, 2021 |
40Plan | CVE-2022-26279No exploit | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.eyoucms · eyoucms · CWE-425 | Critical9.8 | — | 1.8% | Mar 24, 2022 |
39Monitor | CVE-2022-26273No exploit | EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.eyoucms · eyoucms | Critical9.8 | — | 1.2% | Mar 27, 2022 |
39Monitor | CVE-2023-42286No exploit | There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system coeyoucms · eyoucms · CWE-434 | Critical9.8 | — | 1.0% | Mar 14, 2024 |
35Monitor | CVE-2024-3431No exploit | EyouCMS Backend deserializationeyoucms · eyoucms · CWE-502 | High8.8 | — | 0.7% | Apr 7, 2024 |
35Monitor | CVE-2020-19669No exploit | Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admineyoucms · eyoucms · CWE-352 | High8.8 | — | 0.6% | Aug 18, 2021 |
35Monitor | CVE-2020-18129No exploit | A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.eyoucms · eyoucms · CWE-352 | High8.8 | — | 0.6% | Oct 22, 2020 |
35Monitor | CVE-2020-20642No exploit | Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admieyoucms · eyoucms · CWE-352 | High8.8 | — | 0.6% | Aug 19, 2021 |
35Monitor | CVE-2022-36225No exploit | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.eyoucms · eyoucms · CWE-352 | High8.8 | — | 0.5% | Aug 19, 2022 |
35Monitor | CVE-2022-41500No exploit | EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membereyoucms · eyoucms · CWE-352 | High8.8 | — | 0.4% | Oct 18, 2022 |
35Monitor | CVE-2022-43323No exploit | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Membereyoucms · eyoucms · CWE-352 | High8.8 | — | 0.4% | Nov 14, 2022 |
35Monitor | CVE-2022-44387No exploit | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Memeyoucms · eyoucms · CWE-352 | High8.8 | — | 0.3% | Nov 14, 2022 |
32Monitor | CVE-2021-46255No exploit | eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.eyoucms · eyoucms | High8.1 | — | 1.1% | Jan 13, 2022 |
30Monitor | CVE-2021-39500No exploit | Eyoucms 1.5.4 is vulnerable to Directory Traversal.eyoucms · eyoucms · CWE-22 | High7.5 | — | 1.5% | Sep 7, 2021 |
30Monitor | CVE-2024-48196No exploit | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.eyoucms · eyoucms | High7.5 | — | 0.5% | Oct 28, 2024 |
30Monitor | CVE-2025-65868No exploit | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST requeseyoucms · eyoucms · CWE-611 | High7.5 | — | 0.4% | Dec 3, 2025 |
28Monitor | CVE-2023-37645Proof of concept | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.eyoucms · eyoucms · CWE-668 | Medium5.3 | — | 24.9% | Jul 20, 2023 |
28Monitor | CVE-2021-42194No exploit | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ Steyoucms · eyoucms · CWE-611 | High7.2 | — | 1.1% | Mar 20, 2022 |
26Monitor | CVE-2022-44389No exploit | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.eyoucms · eyoucms · CWE-352 | Medium6.5 | — | 0.2% | Nov 14, 2022 |
25Monitor | CVE-2021-39501Proof of concept | EyouCMS 1.5.4 is vulnerable to Open Redirect.eyoucms · eyoucms · CWE-601 | Medium6.1 | — | 3.6% | Sep 7, 2021 |
24Monitor | CVE-2020-28146No exploit | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.eyoucms · eyoucms · CWE-79 | Medium6.1 | — | 1.5% | Aug 18, 2021 |
24Monitor | CVE-2023-41597Proof of concept | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.eyoucms · eyoucms · CWE-79 | Medium6.1 | — | 1.2% | Nov 15, 2023 |
24Monitor | CVE-2021-39499No exploit | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTMeyoucms · eyoucms · CWE-79 | Medium6.1 | — | 1.2% | Sep 7, 2021 |
24Monitor | CVE-2024-22927Proof of concept | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via craftedeyoucms · eyoucms · CWE-79 | Medium6.1 | — | 1.0% | Feb 1, 2024 |
- CVE-2020-2400040Plan
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti
CriticalCVSS 9.8No exploitEPSS 2%eyoucms · eyoucmsNov 3, 2021
- CVE-2021-3949740Plan
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
CriticalCVSS 9.8No exploitEPSS 2%eyoucms · eyoucmsSep 7, 2021
- CVE-2022-2627940Plan
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
CriticalCVSS 9.8No exploitEPSS 2%eyoucms · eyoucmsMar 24, 2022
- CVE-2022-2627339Monitor
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
CriticalCVSS 9.8No exploitEPSS 1%eyoucms · eyoucmsMar 27, 2022
- CVE-2023-4228639Monitor
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co
CriticalCVSS 9.8No exploitEPSS 1%eyoucms · eyoucmsMar 14, 2024
- CVE-2024-343135Monitor
EyouCMS Backend deserialization
HighCVSS 8.8No exploitEPSS 1%eyoucms · eyoucmsApr 7, 2024
- CVE-2020-1966935Monitor
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin
HighCVSS 8.8No exploitEPSS 1%eyoucms · eyoucmsAug 18, 2021
- CVE-2020-1812935Monitor
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
HighCVSS 8.8No exploitEPSS 1%eyoucms · eyoucmsOct 22, 2020
- CVE-2020-2064235Monitor
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi
HighCVSS 8.8No exploitEPSS 1%eyoucms · eyoucmsAug 19, 2021
- CVE-2022-3622535Monitor
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
HighCVSS 8.8No exploitEPSS 0%eyoucms · eyoucmsAug 19, 2022
- CVE-2022-4150035Monitor
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member
HighCVSS 8.8No exploitEPSS 0%eyoucms · eyoucmsOct 18, 2022
- CVE-2022-4332335Monitor
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member
HighCVSS 8.8No exploitEPSS 0%eyoucms · eyoucmsNov 14, 2022
- CVE-2022-4438735Monitor
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem
HighCVSS 8.8No exploitEPSS 0%eyoucms · eyoucmsNov 14, 2022
- CVE-2021-4625532Monitor
eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
HighCVSS 8.1No exploitEPSS 1%eyoucms · eyoucmsJan 13, 2022
- CVE-2021-3950030Monitor
Eyoucms 1.5.4 is vulnerable to Directory Traversal.
HighCVSS 7.5No exploitEPSS 1%eyoucms · eyoucmsSep 7, 2021
- CVE-2024-4819630Monitor
An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
HighCVSS 7.5No exploitEPSS 1%eyoucms · eyoucmsOct 28, 2024
- CVE-2025-6586830Monitor
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques
HighCVSS 7.5No exploitEPSS 0%eyoucms · eyoucmsDec 3, 2025
- CVE-2023-3764528Monitor
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
MediumCVSS 5.3Proof of conceptEPSS 25%eyoucms · eyoucmsJul 20, 2023
- CVE-2021-4219428Monitor
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St
HighCVSS 7.2No exploitEPSS 1%eyoucms · eyoucmsMar 20, 2022
- CVE-2022-4438926Monitor
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.
MediumCVSS 6.5No exploitEPSS 0%eyoucms · eyoucmsNov 14, 2022
- CVE-2021-3950125Monitor
EyouCMS 1.5.4 is vulnerable to Open Redirect.
MediumCVSS 6.1Proof of conceptEPSS 4%eyoucms · eyoucmsSep 7, 2021
- CVE-2020-2814624Monitor
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
MediumCVSS 6.1No exploitEPSS 1%eyoucms · eyoucmsAug 18, 2021
- CVE-2023-4159724Monitor
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
MediumCVSS 6.1Proof of conceptEPSS 1%eyoucms · eyoucmsNov 15, 2023
- CVE-2021-3949924Monitor
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 6.1No exploitEPSS 1%eyoucms · eyoucmsSep 7, 2021
- CVE-2024-2292724Monitor
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted
MediumCVSS 6.1Proof of conceptEPSS 1%eyoucms · eyoucmsFeb 1, 2024