Записи eyoucms
75 опубликованных записей вендора eyoucms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 1,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')47
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
75 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-24000Эксплойта нет | SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tieyoucms · eyoucms · CWE-89 | Критическая9,8 | — | 2,4 % | 3 нояб. 2021 г. |
40В плане | CVE-2021-39497Эксплойта нет | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.eyoucms · eyoucms · CWE-918 | Критическая9,8 | — | 2,4 % | 7 сент. 2021 г. |
40В плане | CVE-2022-26279Эксплойта нет | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.eyoucms · eyoucms · CWE-425 | Критическая9,8 | — | 1,8 % | 24 мар. 2022 г. |
39Наблюдать | CVE-2022-26273Эксплойта нет | EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.eyoucms · eyoucms | Критическая9,8 | — | 1,2 % | 27 мар. 2022 г. |
39Наблюдать | CVE-2023-42286Эксплойта нет | There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system coeyoucms · eyoucms · CWE-434 | Критическая9,8 | — | 1,0 % | 14 мар. 2024 г. |
35Наблюдать | CVE-2024-3431Эксплойта нет | EyouCMS Backend deserializationeyoucms · eyoucms · CWE-502 | Высокая8,8 | — | 0,7 % | 7 апр. 2024 г. |
35Наблюдать | CVE-2020-19669Эксплойта нет | Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admineyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,6 % | 18 авг. 2021 г. |
35Наблюдать | CVE-2020-18129Эксплойта нет | A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.eyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,6 % | 22 окт. 2020 г. |
35Наблюдать | CVE-2020-20642Эксплойта нет | Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admieyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,6 % | 19 авг. 2021 г. |
35Наблюдать | CVE-2022-36225Эксплойта нет | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.eyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,5 % | 19 авг. 2022 г. |
35Наблюдать | CVE-2022-41500Эксплойта нет | EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membereyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,4 % | 18 окт. 2022 г. |
35Наблюдать | CVE-2022-43323Эксплойта нет | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Membereyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,4 % | 14 нояб. 2022 г. |
35Наблюдать | CVE-2022-44387Эксплойта нет | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Memeyoucms · eyoucms · CWE-352 | Высокая8,8 | — | 0,3 % | 14 нояб. 2022 г. |
32Наблюдать | CVE-2021-46255Эксплойта нет | eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.eyoucms · eyoucms | Высокая8,1 | — | 1,1 % | 13 янв. 2022 г. |
30Наблюдать | CVE-2021-39500Эксплойта нет | Eyoucms 1.5.4 is vulnerable to Directory Traversal.eyoucms · eyoucms · CWE-22 | Высокая7,5 | — | 1,5 % | 7 сент. 2021 г. |
30Наблюдать | CVE-2024-48196Эксплойта нет | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.eyoucms · eyoucms | Высокая7,5 | — | 0,5 % | 28 окт. 2024 г. |
30Наблюдать | CVE-2025-65868Эксплойта нет | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST requeseyoucms · eyoucms · CWE-611 | Высокая7,5 | — | 0,4 % | 3 дек. 2025 г. |
28Наблюдать | CVE-2023-37645Proof of concept | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.eyoucms · eyoucms · CWE-668 | Средняя5,3 | — | 24,9 % | 20 июл. 2023 г. |
28Наблюдать | CVE-2021-42194Эксплойта нет | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ Steyoucms · eyoucms · CWE-611 | Высокая7,2 | — | 1,1 % | 20 мар. 2022 г. |
26Наблюдать | CVE-2022-44389Эксплойта нет | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.eyoucms · eyoucms · CWE-352 | Средняя6,5 | — | 0,2 % | 14 нояб. 2022 г. |
25Наблюдать | CVE-2021-39501Proof of concept | EyouCMS 1.5.4 is vulnerable to Open Redirect.eyoucms · eyoucms · CWE-601 | Средняя6,1 | — | 3,6 % | 7 сент. 2021 г. |
24Наблюдать | CVE-2020-28146Эксплойта нет | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.eyoucms · eyoucms · CWE-79 | Средняя6,1 | — | 1,5 % | 18 авг. 2021 г. |
24Наблюдать | CVE-2023-41597Proof of concept | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.eyoucms · eyoucms · CWE-79 | Средняя6,1 | — | 1,2 % | 15 нояб. 2023 г. |
24Наблюдать | CVE-2021-39499Эксплойта нет | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTMeyoucms · eyoucms · CWE-79 | Средняя6,1 | — | 1,2 % | 7 сент. 2021 г. |
24Наблюдать | CVE-2024-22927Proof of concept | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via craftedeyoucms · eyoucms · CWE-79 | Средняя6,1 | — | 1,0 % | 1 февр. 2024 г. |
- CVE-2020-2400040В плане
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eyoucms · eyoucms3 нояб. 2021 г.
- CVE-2021-3949740В плане
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eyoucms · eyoucms7 сент. 2021 г.
- CVE-2022-2627940В плане
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eyoucms · eyoucms24 мар. 2022 г.
- CVE-2022-2627339Наблюдать
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eyoucms · eyoucms27 мар. 2022 г.
- CVE-2023-4228639Наблюдать
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %eyoucms · eyoucms14 мар. 2024 г.
- CVE-2024-343135Наблюдать
EyouCMS Backend deserialization
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eyoucms · eyoucms7 апр. 2024 г.
- CVE-2020-1966935Наблюдать
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eyoucms · eyoucms18 авг. 2021 г.
- CVE-2020-1812935Наблюдать
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eyoucms · eyoucms22 окт. 2020 г.
- CVE-2020-2064235Наблюдать
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eyoucms · eyoucms19 авг. 2021 г.
- CVE-2022-3622535Наблюдать
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %eyoucms · eyoucms19 авг. 2022 г.
- CVE-2022-4150035Наблюдать
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %eyoucms · eyoucms18 окт. 2022 г.
- CVE-2022-4332335Наблюдать
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %eyoucms · eyoucms14 нояб. 2022 г.
- CVE-2022-4438735Наблюдать
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %eyoucms · eyoucms14 нояб. 2022 г.
- CVE-2021-4625532Наблюдать
eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %eyoucms · eyoucms13 янв. 2022 г.
- CVE-2021-3950030Наблюдать
Eyoucms 1.5.4 is vulnerable to Directory Traversal.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %eyoucms · eyoucms7 сент. 2021 г.
- CVE-2024-4819630Наблюдать
An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %eyoucms · eyoucms28 окт. 2024 г.
- CVE-2025-6586830Наблюдать
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %eyoucms · eyoucms3 дек. 2025 г.
- CVE-2023-3764528Наблюдать
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
СредняяCVSS 5,3Proof of conceptEPSS 25 %eyoucms · eyoucms20 июл. 2023 г.
- CVE-2021-4219428Наблюдать
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %eyoucms · eyoucms20 мар. 2022 г.
- CVE-2022-4438926Наблюдать
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %eyoucms · eyoucms14 нояб. 2022 г.
- CVE-2021-3950125Наблюдать
EyouCMS 1.5.4 is vulnerable to Open Redirect.
СредняяCVSS 6,1Proof of conceptEPSS 4 %eyoucms · eyoucms7 сент. 2021 г.
- CVE-2020-2814624Наблюдать
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eyoucms · eyoucms18 авг. 2021 г.
- CVE-2023-4159724Наблюдать
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
СредняяCVSS 6,1Proof of conceptEPSS 1 %eyoucms · eyoucms15 нояб. 2023 г.
- CVE-2021-3949924Наблюдать
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eyoucms · eyoucms7 сент. 2021 г.
- CVE-2024-2292724Наблюдать
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted
СредняяCVSS 6,1Proof of conceptEPSS 1 %eyoucms · eyoucms1 февр. 2024 г.