CVE-2026-7389
- EPSS 0.26%
- Veröffentlicht 29.04.2026 15:30:18
- Zuletzt bearbeitet 29.04.2026 21:16:21
A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remo...
CVE-2026-7388
- EPSS 0.24%
- Veröffentlicht 29.04.2026 15:15:16
- Zuletzt bearbeitet 29.04.2026 21:16:21
A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack ...
CVE-2026-6561
- EPSS 0.28%
- Veröffentlicht 19.04.2026 07:15:11
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is p...
CVE-2026-1107
- EPSS 0.48%
- Veröffentlicht 18.01.2026 00:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload. The ...
CVE-2025-15375
- EPSS 0.37%
- Veröffentlicht 31.12.2025 05:02:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deseriali...
CVE-2025-15374
- EPSS 0.21%
- Veröffentlicht 31.12.2025 04:32:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing a manipulation of the argument content results in cross site scripting...
CVE-2025-15373
- EPSS 0.22%
- Veröffentlicht 31.12.2025 04:02:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exp...
CVE-2025-15143
- EPSS 0.33%
- Veröffentlicht 28.12.2025 16:15:51
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/FilemanagerLogic.php of the component Backend Template Management. The manipulation of the argument content r...
CVE-2025-65868
- EPSS 0.37%
- Veröffentlicht 03.12.2025 00:00:00
- Zuletzt bearbeitet 16.12.2025 19:13:40
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
CVE-2025-52335
- EPSS 0.19%
- Veröffentlicht 14.08.2025 00:00:00
- Zuletzt bearbeitet 18.08.2025 15:00:05
EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.