📦 Eyoucms

by Eyoucms

🔍 What is Eyoucms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-42286

CRITICAL CVSS 9.8 Mar 14, 2024

This vulnerability allows attackers to include arbitrary PHP files in eyoucms v1.6.4 through template configuration manipulation, leading to remote code execution. Attackers can execute system command...

CVE-2022-26279

CRITICAL CVSS 9.8 Mar 24, 2022

EyouCMS v1.5.5 lacks access control on the /data/sqldata component, allowing unauthenticated attackers to directly access sensitive database files. This affects all deployments using the vulnerable ve...

CVE-2020-24000

CRITICAL CVSS 9.8 Nov 3, 2021

This SQL injection vulnerability in eyoucms v1.4.7 allows attackers to execute arbitrary SQL commands via the tid parameter in index.php. Attackers can potentially read, modify, or delete database con...

CVE-2021-39497

CRITICAL CVSS 9.8 Sep 7, 2021

CVE-2021-39497 is a Server-Side Request Forgery (SSRF) vulnerability in eyoucms 1.5.4 that allows attackers to inject URLs via the saveRemote() function, potentially accessing internal systems. This a...

CVE-2025-65868

HIGH CVSS 7.5 Dec 3, 2025

This XML external entity (XXE) injection vulnerability in eyoucms v1.7.1 allows remote attackers to cause denial of service by sending specially crafted POST requests. Attackers can exploit this to cr...

CVE-2024-48196

HIGH CVSS 7.5 Oct 28, 2024

A remote attacker can exploit this vulnerability in eyouCMS v1.6.7 by sending a crafted script to the post parameter, potentially exposing sensitive information. This affects all systems running the v...

CVE-2021-42194

HIGH CVSS 7.2 Mar 20, 2022

This XXE vulnerability in EyouCMS allows attackers to read sensitive files from the server or perform server-side request forgery by sending malicious XML data. It affects all users running vulnerable...

CVE-2021-39500

HIGH CVSS 7.5 Sep 7, 2021

Eyoucms 1.5.4 contains a directory traversal vulnerability that allows attackers to write files outside intended directories by injecting '../' sequences in parameters. This affects all systems runnin...

CVE-2026-1107

MEDIUM CVSS 6.3 Jan 18, 2026

This vulnerability in EyouCMS allows attackers to perform unrestricted file uploads via manipulation of the 'viewfile' parameter in the Member Avatar Handler component. This can lead to remote code ex...

CVE-2025-15375

MEDIUM CVSS 6.3 Dec 31, 2025

CVE-2025-15375 is a remote code execution vulnerability in EyouCMS versions up to 1.7.7, caused by insecure deserialization in the arcpagelist handler. Attackers can exploit this flaw by sending speci...

CVE-2025-15373

MEDIUM CVSS 6.3 Dec 31, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in EyouCMS versions up to 1.7.7. Attackers can exploit the saveRemote function in application/function.php to make the server send...

CVE-2025-15143

MEDIUM CVSS 4.7 Dec 28, 2025

This SQL injection vulnerability in EyouCMS allows attackers to manipulate database queries through the backend template management component. It affects EyouCMS versions up to 1.7.6 and can be exploi...

CVE-2024-52680

MEDIUM CVSS 6.1 Aug 7, 2025

EyouCMS 1.6.7 contains a cross-site scripting vulnerability in the admin system configuration interface that allows attackers to inject malicious scripts. This affects administrators who access the vu...

CVE-2024-11211

MEDIUM CVSS 4.7 Nov 14, 2024

A critical vulnerability in EyouCMS allows unrestricted file uploads via the Website Logo Handler component, enabling attackers to upload malicious files remotely. This affects EyouCMS versions up to ...

CVE-2025-15374

LOW CVSS 3.5 Dec 31, 2025

This vulnerability allows attackers to inject malicious scripts into the Ask module of EyouCMS through content manipulation, resulting in cross-site scripting (XSS). The attack can be executed remotel...