Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1107 A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av… Eyoucms Mitigation only Fix from $2,3002026-01-18 HIGH 8.8 CVE-2025-15375 A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the… Eyoucms 1.7.8+ Fix from $1,9502025-12-31 MEDIUM 5.4 CVE-2025-15374 A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co… Eyoucms 1.7.8+ Fix from $1,6002025-12-31 HIGH 7.2 CVE-2025-15143 A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/Filemana… Eyoucms after 1.7.6 Fix from $1,9502025-12-28 HIGH 7.5 CVE-2025-65868 XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request. Eyoucms No fix yet Fix from $1,9502025-12-03 MEDIUM 6.1 CVE-2025-52335 EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information. Eyoucms Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.1 CVE-2024-52680 EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. Eyoucms No fix yet Fix from $1,6002025-08-07 HIGH 7.2 CVE-2024-11211 A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. … Eyoucms after 1.6.7 Fix from $1,9502024-11-14 MEDIUM 5.4 CVE-2024-11210 A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi… Eyoucms No fix yet Fix from $1,6002024-11-14 HIGH 7.5 CVE-2024-48196 An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. Eyoucms Mitigation only Fix from $1,9502024-10-28 MEDIUM 6.1 CVE-2024-48195 Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post param… Eyoucms Mitigation only Fix from $1,6002024-10-28 HIGH 8.8 CVE-2024-3431 A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&… Eyoucms Mitigation only Fix from $1,9502024-04-07 CRITICAL 9.8 CVE-2023-42286 There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th… Eyoucms No fix yet Fix from $2,3002024-03-14 MEDIUM 6.1 CVE-2024-23031 Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23032 Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23033 Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-23034 Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 6.1 CVE-2024-22927 Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. Eyoucms No fix yet Fix from $1,6002024-02-01 MEDIUM 5.4 CVE-2023-50566 A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted … Eyoucms No fix yet Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-46935 eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users. Eyoucms No fix yet Fix from $1,6002023-11-21 MEDIUM 6.1 CVE-2023-41597 EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. Eyoucms No fix yet Fix from $1,6002023-11-15 MEDIUM 5.3 CVE-2023-37645EPSS 25% eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. Eyoucms No fix yet Fix from $1,6002023-07-20 MEDIUM 5.4 CVE-2023-37132 A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts … Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37133 A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37134 A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37135 A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or H… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-37136 A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web… Eyoucms No fix yet Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-36093 There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of … Eyoucms No fix yet Fix from $1,6002023-06-22 MEDIUM 5.4 CVE-2023-33492 EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS). Eyoucms No fix yet Fix from $1,6002023-06-12 MEDIUM 6.1 CVE-2023-30125 EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS). Eyoucms No fix yet Fix from $1,6002023-04-28