Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eyoucms CRITICAL 9.8
CVE-2026-1107

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…

Mitigation only
Fix from $2,300 2026-01-18
Eyoucms HIGH 8.8
CVE-2025-15375

A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the…

Fix: 1.7.8+
Fix from $1,950 2025-12-31
Eyoucms MEDIUM 5.4
CVE-2025-15374

A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co…

Fix: 1.7.8+
Fix from $1,600 2025-12-31
Eyoucms HIGH 7.2
CVE-2025-15143

A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/Filemana…

Fix: after 1.7.6
Fix from $1,950 2025-12-28
Eyoucms HIGH 7.5
CVE-2025-65868

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

No fix yet
Fix from $1,950 2025-12-03
Eyoucms MEDIUM 6.1
CVE-2025-52335

EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

Mitigation only
Fix from $1,600 2025-08-14
Eyoucms MEDIUM 6.1
CVE-2024-52680

EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

No fix yet
Fix from $1,600 2025-08-07
Eyoucms HIGH 7.2
CVE-2024-11211

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. …

Fix: after 1.6.7
Fix from $1,950 2024-11-14
Eyoucms MEDIUM 5.4
CVE-2024-11210

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi…

No fix yet
Fix from $1,600 2024-11-14
Eyoucms HIGH 7.5
CVE-2024-48196

An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

Mitigation only
Fix from $1,950 2024-10-28
Eyoucms MEDIUM 6.1
CVE-2024-48195

Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post param…

Mitigation only
Fix from $1,600 2024-10-28
Eyoucms HIGH 8.8
CVE-2024-3431

A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&…

Mitigation only
Fix from $1,950 2024-04-07
Eyoucms CRITICAL 9.8
CVE-2023-42286

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th…

No fix yet
Fix from $2,300 2024-03-14
Eyoucms MEDIUM 6.1
CVE-2024-23031

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23032

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23033

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23034

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-22927

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 5.4
CVE-2023-50566

A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

No fix yet
Fix from $1,600 2023-12-14
Eyoucms MEDIUM 5.4
CVE-2023-46935

eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

No fix yet
Fix from $1,600 2023-11-21
Eyoucms MEDIUM 6.1
CVE-2023-41597

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

No fix yet
Fix from $1,600 2023-11-15
Eyoucms MEDIUM 5.3
CVE-2023-37645EPSS 25%

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

No fix yet
Fix from $1,600 2023-07-20
Eyoucms MEDIUM 5.4
CVE-2023-37132

A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts …

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37133

A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37134

A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37135

A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or H…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37136

A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-36093

There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of …

No fix yet
Fix from $1,600 2023-06-22
Eyoucms MEDIUM 5.4
CVE-2023-33492

EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-06-12
Eyoucms MEDIUM 6.1
CVE-2023-30125

EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-04-28