Vulnerability index

Browse CVEs

53 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1107 A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av… Eyoucms Mitigation only Fix from $2,3002026-01-18 HIGH 7.5 CVE-2025-65868 XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request. Eyoucms No fix yet Fix from $1,9502025-12-03 MEDIUM 6.1 CVE-2025-52335 EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information. Eyoucms Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.1 CVE-2024-52680 EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. Eyoucms No fix yet Fix from $1,6002025-08-07 MEDIUM 5.4 CVE-2024-11210 A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi… Eyoucms No fix yet Fix from $1,6002024-11-14 HIGH 7.5 CVE-2024-48196 An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. Eyoucms Mitigation only Fix from $1,9502024-10-28 MEDIUM 6.1 CVE-2024-48195 Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post param… Eyoucms Mitigation only Fix from $1,6002024-10-28 HIGH 8.8 CVE-2024-3431 A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&… Eyoucms Mitigation only Fix from $1,9502024-04-07 CRITICAL 9.8 CVE-2023-42286 There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th… Eyoucms No fix yet Fix from $2,3002024-03-14 MEDIUM 6.1 CVE-2024-23031 Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23032 Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23033 Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23034 Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-22927 Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 5.4 CVE-2023-50566 A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted … Eyoucms No fix yet Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-46935 eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users. Eyoucms No fix yet Fix from $1,6002023-11-21 MEDIUM 6.1 CVE-2023-41597 EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. Eyoucms No fix yet Fix from $1,6002023-11-15 MEDIUM 5.3 CVE-2023-37645EPSS 25% eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. Eyoucms No fix yet Fix from $1,6002023-07-20 MEDIUM 5.4 CVE-2023-37132 A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts … Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37133 A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37134 A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37135 A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or H… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37136 A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-36093 There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of … Eyoucms No fix yet Fix from $1,6002023-06-22 MEDIUM 5.4 CVE-2023-33492 EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS). Eyoucms No fix yet Fix from $1,6002023-06-12 MEDIUM 6.1 CVE-2023-30125 EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS). Eyoucms No fix yet Fix from $1,6002023-04-28 MEDIUM 6.1 CVE-2023-2057 A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Ar… Eyoucms No fix yet Fix from $1,6002023-04-14 MEDIUM 5.4 CVE-2022-45755 Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic info… Eyoucms No fix yet Fix from $1,6002023-02-08 MEDIUM 5.4 CVE-2021-39428 Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via… Eyoucms No fix yet Fix from $1,6002022-12-15 MEDIUM 5.4 CVE-2022-45280 A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or … Eyoucms No fix yet Fix from $1,6002022-11-23