Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-1107
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…
Eyoucms
Mitigation only
HIGH 8.8
CVE-2025-15375
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the…
Eyoucms
1.7.8+
MEDIUM 5.4
CVE-2025-15374
A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co…
Eyoucms
1.7.8+
HIGH 7.2
CVE-2025-15143
A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/Filemana…
Eyoucms
after 1.7.6
HIGH 7.5
CVE-2025-65868
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2025-52335
EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.
Eyoucms
Mitigation only
MEDIUM 6.1
CVE-2024-52680
EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
Eyoucms
No fix yet
HIGH 7.2
CVE-2024-11211
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. …
Eyoucms
after 1.6.7
MEDIUM 5.4
CVE-2024-11210
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi…
Eyoucms
No fix yet
HIGH 7.5
CVE-2024-48196
An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
Eyoucms
Mitigation only
MEDIUM 6.1
CVE-2024-48195
Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post param…
Eyoucms
Mitigation only
HIGH 8.8
CVE-2024-3431
A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&…
Eyoucms
Mitigation only
CRITICAL 9.8
CVE-2023-42286
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th…
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2024-23031
Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2024-23032
Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2024-23033
Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2024-23034
Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2024-22927
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-50566
A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted …
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-46935
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2023-41597
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
Eyoucms
No fix yet
MEDIUM 5.3
CVE-2023-37645EPSS 25%
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-37132
A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts …
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-37133
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-37134
A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts…
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-37135
A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or H…
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-37136
A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web…
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-36093
There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of …
Eyoucms
No fix yet
MEDIUM 5.4
CVE-2023-33492
EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).
Eyoucms
No fix yet
MEDIUM 6.1
CVE-2023-30125
EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).
Eyoucms
No fix yet