Vulnerability index

Browse CVEs

53 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Eyoucms CRITICAL 9.8
CVE-2026-1107

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…

Mitigation only
Fix from $2,300 2026-01-18
Eyoucms HIGH 7.5
CVE-2025-65868

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

No fix yet
Fix from $1,950 2025-12-03
Eyoucms MEDIUM 6.1
CVE-2025-52335

EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

Mitigation only
Fix from $1,600 2025-08-14
Eyoucms MEDIUM 6.1
CVE-2024-52680

EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

No fix yet
Fix from $1,600 2025-08-07
Eyoucms MEDIUM 5.4
CVE-2024-11210

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi…

No fix yet
Fix from $1,600 2024-11-14
Eyoucms HIGH 7.5
CVE-2024-48196

An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

Mitigation only
Fix from $1,950 2024-10-28
Eyoucms MEDIUM 6.1
CVE-2024-48195

Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post param…

Mitigation only
Fix from $1,600 2024-10-28
Eyoucms HIGH 8.8
CVE-2024-3431

A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&…

Mitigation only
Fix from $1,950 2024-04-07
Eyoucms CRITICAL 9.8
CVE-2023-42286

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th…

No fix yet
Fix from $2,300 2024-03-14
Eyoucms MEDIUM 6.1
CVE-2024-23031

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23032

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23033

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-23034

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 6.1
CVE-2024-22927

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

No fix yet
Fix from $1,600 2024-02-01
Eyoucms MEDIUM 5.4
CVE-2023-50566

A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

No fix yet
Fix from $1,600 2023-12-14
Eyoucms MEDIUM 5.4
CVE-2023-46935

eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

No fix yet
Fix from $1,600 2023-11-21
Eyoucms MEDIUM 6.1
CVE-2023-41597

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

No fix yet
Fix from $1,600 2023-11-15
Eyoucms MEDIUM 5.3
CVE-2023-37645EPSS 25%

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

No fix yet
Fix from $1,600 2023-07-20
Eyoucms MEDIUM 5.4
CVE-2023-37132

A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts …

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37133

A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37134

A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37135

A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or H…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-37136

A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2023-07-06
Eyoucms MEDIUM 5.4
CVE-2023-36093

There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of …

No fix yet
Fix from $1,600 2023-06-22
Eyoucms MEDIUM 5.4
CVE-2023-33492

EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-06-12
Eyoucms MEDIUM 6.1
CVE-2023-30125

EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-04-28
Eyoucms MEDIUM 6.1
CVE-2023-2057

A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Ar…

No fix yet
Fix from $1,600 2023-04-14
Eyoucms MEDIUM 5.4
CVE-2022-45755

Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic info…

No fix yet
Fix from $1,600 2023-02-08
Eyoucms MEDIUM 5.4
CVE-2021-39428

Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via…

No fix yet
Fix from $1,600 2022-12-15
Eyoucms MEDIUM 5.4
CVE-2022-45280

A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or …

No fix yet
Fix from $1,600 2022-11-23