eyoucms kayıtları
eyoucms üreticisine ait 75 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %1,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')47
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
75 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-24000İstismar yok | SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tieyoucms · eyoucms · CWE-89 | Kritik9,8 | — | %2,4 | 3 Kas 2021 |
40Planlayın | CVE-2021-39497İstismar yok | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.eyoucms · eyoucms · CWE-918 | Kritik9,8 | — | %2,4 | 7 Eyl 2021 |
40Planlayın | CVE-2022-26279İstismar yok | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.eyoucms · eyoucms · CWE-425 | Kritik9,8 | — | %1,8 | 24 Mar 2022 |
39İzleyin | CVE-2022-26273İstismar yok | EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.eyoucms · eyoucms | Kritik9,8 | — | %1,2 | 27 Mar 2022 |
39İzleyin | CVE-2023-42286İstismar yok | There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system coeyoucms · eyoucms · CWE-434 | Kritik9,8 | — | %1,0 | 14 Mar 2024 |
35İzleyin | CVE-2024-3431İstismar yok | EyouCMS Backend deserializationeyoucms · eyoucms · CWE-502 | Yüksek8,8 | — | %0,7 | 7 Nis 2024 |
35İzleyin | CVE-2020-19669İstismar yok | Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admineyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,6 | 18 Ağu 2021 |
35İzleyin | CVE-2020-18129İstismar yok | A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.eyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,6 | 22 Eki 2020 |
35İzleyin | CVE-2020-20642İstismar yok | Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admieyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,6 | 19 Ağu 2021 |
35İzleyin | CVE-2022-36225İstismar yok | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.eyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,5 | 19 Ağu 2022 |
35İzleyin | CVE-2022-41500İstismar yok | EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membereyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,4 | 18 Eki 2022 |
35İzleyin | CVE-2022-43323İstismar yok | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Membereyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,4 | 14 Kas 2022 |
35İzleyin | CVE-2022-44387İstismar yok | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Memeyoucms · eyoucms · CWE-352 | Yüksek8,8 | — | %0,3 | 14 Kas 2022 |
32İzleyin | CVE-2021-46255İstismar yok | eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.eyoucms · eyoucms | Yüksek8,1 | — | %1,1 | 13 Oca 2022 |
30İzleyin | CVE-2021-39500İstismar yok | Eyoucms 1.5.4 is vulnerable to Directory Traversal.eyoucms · eyoucms · CWE-22 | Yüksek7,5 | — | %1,5 | 7 Eyl 2021 |
30İzleyin | CVE-2024-48196İstismar yok | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.eyoucms · eyoucms | Yüksek7,5 | — | %0,5 | 28 Eki 2024 |
30İzleyin | CVE-2025-65868İstismar yok | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST requeseyoucms · eyoucms · CWE-611 | Yüksek7,5 | — | %0,4 | 3 Ara 2025 |
28İzleyin | CVE-2023-37645Kavram kanıtı | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.eyoucms · eyoucms · CWE-668 | Orta5,3 | — | %24,9 | 20 Tem 2023 |
28İzleyin | CVE-2021-42194İstismar yok | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ Steyoucms · eyoucms · CWE-611 | Yüksek7,2 | — | %1,1 | 20 Mar 2022 |
26İzleyin | CVE-2022-44389İstismar yok | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.eyoucms · eyoucms · CWE-352 | Orta6,5 | — | %0,2 | 14 Kas 2022 |
25İzleyin | CVE-2021-39501Kavram kanıtı | EyouCMS 1.5.4 is vulnerable to Open Redirect.eyoucms · eyoucms · CWE-601 | Orta6,1 | — | %3,6 | 7 Eyl 2021 |
24İzleyin | CVE-2020-28146İstismar yok | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.eyoucms · eyoucms · CWE-79 | Orta6,1 | — | %1,5 | 18 Ağu 2021 |
24İzleyin | CVE-2023-41597Kavram kanıtı | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.eyoucms · eyoucms · CWE-79 | Orta6,1 | — | %1,2 | 15 Kas 2023 |
24İzleyin | CVE-2021-39499İstismar yok | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTMeyoucms · eyoucms · CWE-79 | Orta6,1 | — | %1,2 | 7 Eyl 2021 |
24İzleyin | CVE-2024-22927Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via craftedeyoucms · eyoucms · CWE-79 | Orta6,1 | — | %1,0 | 1 Şub 2024 |
- CVE-2020-2400040Planlayın
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the ti
KritikCVSS 9,8İstismar yokEPSS %2eyoucms · eyoucms3 Kas 2021
- CVE-2021-3949740Planlayın
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
KritikCVSS 9,8İstismar yokEPSS %2eyoucms · eyoucms7 Eyl 2021
- CVE-2022-2627940Planlayın
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
KritikCVSS 9,8İstismar yokEPSS %2eyoucms · eyoucms24 Mar 2022
- CVE-2022-2627339İzleyin
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
KritikCVSS 9,8İstismar yokEPSS %1eyoucms · eyoucms27 Mar 2022
- CVE-2023-4228639İzleyin
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system co
KritikCVSS 9,8İstismar yokEPSS %1eyoucms · eyoucms14 Mar 2024
- CVE-2024-343135İzleyin
EyouCMS Backend deserialization
YüksekCVSS 8,8İstismar yokEPSS %1eyoucms · eyoucms7 Nis 2024
- CVE-2020-1966935İzleyin
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin
YüksekCVSS 8,8İstismar yokEPSS %1eyoucms · eyoucms18 Ağu 2021
- CVE-2020-1812935İzleyin
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
YüksekCVSS 8,8İstismar yokEPSS %1eyoucms · eyoucms22 Eki 2020
- CVE-2020-2064235İzleyin
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admi
YüksekCVSS 8,8İstismar yokEPSS %1eyoucms · eyoucms19 Ağu 2021
- CVE-2022-3622535İzleyin
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
YüksekCVSS 8,8İstismar yokEPSS %0eyoucms · eyoucms19 Ağu 2022
- CVE-2022-4150035İzleyin
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Member
YüksekCVSS 8,8İstismar yokEPSS %0eyoucms · eyoucms18 Eki 2022
- CVE-2022-4332335İzleyin
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member
YüksekCVSS 8,8İstismar yokEPSS %0eyoucms · eyoucms14 Kas 2022
- CVE-2022-4438735İzleyin
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Mem
YüksekCVSS 8,8İstismar yokEPSS %0eyoucms · eyoucms14 Kas 2022
- CVE-2021-4625532İzleyin
eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
YüksekCVSS 8,1İstismar yokEPSS %1eyoucms · eyoucms13 Oca 2022
- CVE-2021-3950030İzleyin
Eyoucms 1.5.4 is vulnerable to Directory Traversal.
YüksekCVSS 7,5İstismar yokEPSS %1eyoucms · eyoucms7 Eyl 2021
- CVE-2024-4819630İzleyin
An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
YüksekCVSS 7,5İstismar yokEPSS %1eyoucms · eyoucms28 Eki 2024
- CVE-2025-6586830İzleyin
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST reques
YüksekCVSS 7,5İstismar yokEPSS %0eyoucms · eyoucms3 Ara 2025
- CVE-2023-3764528İzleyin
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
OrtaCVSS 5,3Kavram kanıtıEPSS %25eyoucms · eyoucms20 Tem 2023
- CVE-2021-4219428İzleyin
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ St
YüksekCVSS 7,2İstismar yokEPSS %1eyoucms · eyoucms20 Mar 2022
- CVE-2022-4438926İzleyin
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.
OrtaCVSS 6,5İstismar yokEPSS %0eyoucms · eyoucms14 Kas 2022
- CVE-2021-3950125İzleyin
EyouCMS 1.5.4 is vulnerable to Open Redirect.
OrtaCVSS 6,1Kavram kanıtıEPSS %4eyoucms · eyoucms7 Eyl 2021
- CVE-2020-2814624İzleyin
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
OrtaCVSS 6,1İstismar yokEPSS %1eyoucms · eyoucms18 Ağu 2021
- CVE-2023-4159724İzleyin
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
OrtaCVSS 6,1Kavram kanıtıEPSS %1eyoucms · eyoucms15 Kas 2023
- CVE-2021-3949924İzleyin
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTM
OrtaCVSS 6,1İstismar yokEPSS %1eyoucms · eyoucms7 Eyl 2021
- CVE-2024-2292724İzleyin
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted
OrtaCVSS 6,1Kavram kanıtıEPSS %1eyoucms · eyoucms1 Şub 2024