Skip to content
Noroxi

eyoucms records

75 published records for vendor eyoucms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
1.3%
Median publish → KEV
No record has entered KEV

All records

75 records
  • SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti

    CriticalCVSS 9.8No exploitEPSS 2%

    eyoucms · eyoucmsNov 3, 2021

  • eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

    CriticalCVSS 9.8No exploitEPSS 2%

    eyoucms · eyoucmsSep 7, 2021

  • EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

    CriticalCVSS 9.8No exploitEPSS 2%

    eyoucms · eyoucmsMar 24, 2022

  • EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

    CriticalCVSS 9.8No exploitEPSS 1%

    eyoucms · eyoucmsMar 27, 2022

  • There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co

    CriticalCVSS 9.8No exploitEPSS 1%

    eyoucms · eyoucmsMar 14, 2024

  • CVE-2024-3431
    35Monitor

    EyouCMS Backend deserialization

    HighCVSS 8.8No exploitEPSS 1%

    eyoucms · eyoucmsApr 7, 2024

  • Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin

    HighCVSS 8.8No exploitEPSS 1%

    eyoucms · eyoucmsAug 18, 2021

  • A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

    HighCVSS 8.8No exploitEPSS 1%

    eyoucms · eyoucmsOct 22, 2020

  • Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi

    HighCVSS 8.8No exploitEPSS 1%

    eyoucms · eyoucmsAug 19, 2021

  • EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

    HighCVSS 8.8No exploitEPSS 0%

    eyoucms · eyoucmsAug 19, 2022

  • EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member

    HighCVSS 8.8No exploitEPSS 0%

    eyoucms · eyoucmsOct 18, 2022

  • EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member

    HighCVSS 8.8No exploitEPSS 0%

    eyoucms · eyoucmsNov 14, 2022

  • EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem

    HighCVSS 8.8No exploitEPSS 0%

    eyoucms · eyoucmsNov 14, 2022

  • eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

    HighCVSS 8.1No exploitEPSS 1%

    eyoucms · eyoucmsJan 13, 2022

  • Eyoucms 1.5.4 is vulnerable to Directory Traversal.

    HighCVSS 7.5No exploitEPSS 1%

    eyoucms · eyoucmsSep 7, 2021

  • An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

    HighCVSS 7.5No exploitEPSS 1%

    eyoucms · eyoucmsOct 28, 2024

  • XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques

    HighCVSS 7.5No exploitEPSS 0%

    eyoucms · eyoucmsDec 3, 2025

  • eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

    MediumCVSS 5.3Proof of conceptEPSS 25%

    eyoucms · eyoucmsJul 20, 2023

  • The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St

    HighCVSS 7.2No exploitEPSS 1%

    eyoucms · eyoucmsMar 20, 2022

  • EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.

    MediumCVSS 6.5No exploitEPSS 0%

    eyoucms · eyoucmsNov 14, 2022

  • EyouCMS 1.5.4 is vulnerable to Open Redirect.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    eyoucms · eyoucmsSep 7, 2021

  • Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    eyoucms · eyoucmsAug 18, 2021

  • EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    eyoucms · eyoucmsNov 15, 2023

  • A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM

    MediumCVSS 6.1No exploitEPSS 1%

    eyoucms · eyoucmsSep 7, 2021

  • Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted

    MediumCVSS 6.1Proof of conceptEPSS 1%

    eyoucms · eyoucmsFeb 1, 2024