CVE-2021-39428
- EPSS 0.53%
- Veröffentlicht 15.12.2022 19:15:16
- Zuletzt bearbeitet 21.04.2025 19:15:16
Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.
CVE-2022-45280
- EPSS 0.34%
- Veröffentlicht 23.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 20:15:37
A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-44390
- EPSS 0.32%
- Veröffentlicht 14.11.2022 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:27:57
A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field.
CVE-2022-44389
- EPSS 0.22%
- Veröffentlicht 14.11.2022 20:15:18
- Zuletzt bearbeitet 30.04.2025 19:15:53
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.
CVE-2022-44387
- EPSS 0.26%
- Veröffentlicht 14.11.2022 20:15:18
- Zuletzt bearbeitet 30.04.2025 19:15:52
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.
CVE-2022-43323
- EPSS 0.37%
- Veröffentlicht 14.11.2022 20:15:17
- Zuletzt bearbeitet 30.04.2025 16:15:27
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
CVE-2022-41500
- EPSS 0.38%
- Veröffentlicht 18.10.2022 23:15:09
- Zuletzt bearbeitet 15.05.2025 16:15:29
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.
CVE-2022-36225
- EPSS 0.39%
- Veröffentlicht 19.08.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:12:37
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
CVE-2022-35509
- EPSS 0.48%
- Veröffentlicht 10.08.2022 20:15:54
- Zuletzt bearbeitet 23.06.2026 16:16:58
An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the at...
CVE-2022-33122
- EPSS 0.45%
- Veröffentlicht 24.06.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:07:34
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.