İçeriğe atla
Noroxi

eyoucms kayıtları

eyoucms üreticisine ait 75 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
7
Düzeltme kaydı olan
%1,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

75 kayıt
  • CVE-2020-24000
    40Planlayın

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti

    KritikCVSS 9,8İstismar yokEPSS %2

    eyoucms · eyoucms3 Kas 2021

  • CVE-2021-39497
    40Planlayın

    eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

    KritikCVSS 9,8İstismar yokEPSS %2

    eyoucms · eyoucms7 Eyl 2021

  • CVE-2022-26279
    40Planlayın

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

    KritikCVSS 9,8İstismar yokEPSS %2

    eyoucms · eyoucms24 Mar 2022

  • CVE-2022-26273
    39İzleyin

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

    KritikCVSS 9,8İstismar yokEPSS %1

    eyoucms · eyoucms27 Mar 2022

  • CVE-2023-42286
    39İzleyin

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co

    KritikCVSS 9,8İstismar yokEPSS %1

    eyoucms · eyoucms14 Mar 2024

  • CVE-2024-3431
    35İzleyin

    EyouCMS Backend deserialization

    YüksekCVSS 8,8İstismar yokEPSS %1

    eyoucms · eyoucms7 Nis 2024

  • CVE-2020-19669
    35İzleyin

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin

    YüksekCVSS 8,8İstismar yokEPSS %1

    eyoucms · eyoucms18 Ağu 2021

  • CVE-2020-18129
    35İzleyin

    A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

    YüksekCVSS 8,8İstismar yokEPSS %1

    eyoucms · eyoucms22 Eki 2020

  • CVE-2020-20642
    35İzleyin

    Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi

    YüksekCVSS 8,8İstismar yokEPSS %1

    eyoucms · eyoucms19 Ağu 2021

  • CVE-2022-36225
    35İzleyin

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

    YüksekCVSS 8,8İstismar yokEPSS %0

    eyoucms · eyoucms19 Ağu 2022

  • CVE-2022-41500
    35İzleyin

    EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member

    YüksekCVSS 8,8İstismar yokEPSS %0

    eyoucms · eyoucms18 Eki 2022

  • CVE-2022-43323
    35İzleyin

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member

    YüksekCVSS 8,8İstismar yokEPSS %0

    eyoucms · eyoucms14 Kas 2022

  • CVE-2022-44387
    35İzleyin

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem

    YüksekCVSS 8,8İstismar yokEPSS %0

    eyoucms · eyoucms14 Kas 2022

  • CVE-2021-46255
    32İzleyin

    eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

    YüksekCVSS 8,1İstismar yokEPSS %1

    eyoucms · eyoucms13 Oca 2022

  • CVE-2021-39500
    30İzleyin

    Eyoucms 1.5.4 is vulnerable to Directory Traversal.

    YüksekCVSS 7,5İstismar yokEPSS %1

    eyoucms · eyoucms7 Eyl 2021

  • CVE-2024-48196
    30İzleyin

    An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

    YüksekCVSS 7,5İstismar yokEPSS %1

    eyoucms · eyoucms28 Eki 2024

  • CVE-2025-65868
    30İzleyin

    XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques

    YüksekCVSS 7,5İstismar yokEPSS %0

    eyoucms · eyoucms3 Ara 2025

  • CVE-2023-37645
    28İzleyin

    eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

    OrtaCVSS 5,3Kavram kanıtıEPSS %25

    eyoucms · eyoucms20 Tem 2023

  • CVE-2021-42194
    28İzleyin

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St

    YüksekCVSS 7,2İstismar yokEPSS %1

    eyoucms · eyoucms20 Mar 2022

  • CVE-2022-44389
    26İzleyin

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.

    OrtaCVSS 6,5İstismar yokEPSS %0

    eyoucms · eyoucms14 Kas 2022

  • CVE-2021-39501
    25İzleyin

    EyouCMS 1.5.4 is vulnerable to Open Redirect.

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    eyoucms · eyoucms7 Eyl 2021

  • CVE-2020-28146
    24İzleyin

    Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eyoucms · eyoucms18 Ağu 2021

  • CVE-2023-41597
    24İzleyin

    EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    eyoucms · eyoucms15 Kas 2023

  • CVE-2021-39499
    24İzleyin

    A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM

    OrtaCVSS 6,1İstismar yokEPSS %1

    eyoucms · eyoucms7 Eyl 2021

  • CVE-2024-22927
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    eyoucms · eyoucms1 Şub 2024