eyoucms CVE Vulnerabilities & Metrics

Focus on eyoucms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About eyoucms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with eyoucms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total eyoucms CVEs: 63
Earliest CVE date: 10 Oct 2019, 12:10 UTC
Latest CVE date: 14 Nov 2024, 15:15 UTC

Latest CVE reference: CVE-2024-11211

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -92.31%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -92.31%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical eyoucms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.06

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 45
4.0-6.9 14
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS eyoucms CVEs

These are the five CVEs with the highest CVSS scores for eyoucms, sorted by severity first and recency.

All CVEs for eyoucms

CVE-2024-11211 eyoucms vulnerability CVSS: 5.8 14 Nov 2024, 15:15 UTC

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11210 eyoucms vulnerability CVSS: 5.5 14 Nov 2024, 15:15 UTC

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-23034 eyoucms vulnerability CVSS: 0 01 Feb 2024, 23:15 UTC

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-23033 eyoucms vulnerability CVSS: 0 01 Feb 2024, 23:15 UTC

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-23032 eyoucms vulnerability CVSS: 0 01 Feb 2024, 23:15 UTC

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-23031 eyoucms vulnerability CVSS: 0 01 Feb 2024, 23:15 UTC

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2024-22927 eyoucms vulnerability CVSS: 0 01 Feb 2024, 23:15 UTC

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

CVE-2023-50566 eyoucms vulnerability CVSS: 0 14 Dec 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter.

CVE-2023-48882 eyoucms vulnerability CVSS: 0 29 Nov 2023, 16:15 UTC

A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Document Properties field at /login.php m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn.

CVE-2023-48881 eyoucms vulnerability CVSS: 0 29 Nov 2023, 16:15 UTC

A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn.

CVE-2023-48880 eyoucms vulnerability CVSS: 0 29 Nov 2023, 16:15 UTC

A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu Name field at /login.php?m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn.

CVE-2023-46935 eyoucms vulnerability CVSS: 0 21 Nov 2023, 07:15 UTC

eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

CVE-2023-41597 eyoucms vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

CVE-2023-37645 eyoucms vulnerability CVSS: 0 20 Jul 2023, 22:15 UTC

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

CVE-2023-37136 eyoucms vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37135 eyoucms vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37134 eyoucms vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37133 eyoucms vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37132 eyoucms vulnerability CVSS: 0 06 Jul 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-36093 eyoucms vulnerability CVSS: 0 22 Jun 2023, 15:15 UTC

There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3

CVE-2023-34657 eyoucms vulnerability CVSS: 0 19 Jun 2023, 04:15 UTC

A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the web_recordnum parameter.

CVE-2023-33492 eyoucms vulnerability CVSS: 0 12 Jun 2023, 13:15 UTC

EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-31708 eyoucms vulnerability CVSS: 0 23 May 2023, 01:15 UTC

A Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a crafted HTML file to the Upload software format function.

CVE-2023-30125 eyoucms vulnerability CVSS: 0 28 Apr 2023, 14:15 UTC

EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-2058 eyoucms vulnerability CVSS: 3.3 14 Apr 2023, 14:15 UTC

A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.

CVE-2023-2057 eyoucms vulnerability CVSS: 3.3 14 Apr 2023, 14:15 UTC

A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Arctype&a=edit of the component New Picture Handler. The manipulation of the argument litpic_loca leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225942 is the identifier assigned to this vulnerability.

CVE-2023-1799 eyoucms vulnerability CVSS: 4.0 02 Apr 2023, 10:15 UTC

A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of the file login.php. The manipulation of the argument tag_tag leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224751.

CVE-2023-1798 eyoucms vulnerability CVSS: 4.0 02 Apr 2023, 10:15 UTC

A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument typename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-224750 is the identifier assigned to this vulnerability.

CVE-2022-45755 eyoucms vulnerability CVSS: 0 08 Feb 2023, 19:15 UTC

Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page.

CVE-2022-45542 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.

CVE-2022-45541 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.

CVE-2022-45540 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.

CVE-2022-45539 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.

CVE-2022-45538 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".

CVE-2022-45537 eyoucms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".

CVE-2021-39428 eyoucms vulnerability CVSS: 0 15 Dec 2022, 19:15 UTC

Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.

CVE-2022-45280 eyoucms vulnerability CVSS: 0 23 Nov 2022, 21:15 UTC

A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2022-44390 eyoucms vulnerability CVSS: 0 14 Nov 2022, 20:15 UTC

A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field.

CVE-2022-44389 eyoucms vulnerability CVSS: 0 14 Nov 2022, 20:15 UTC

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.

CVE-2022-44387 eyoucms vulnerability CVSS: 0 14 Nov 2022, 20:15 UTC

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.

CVE-2022-43323 eyoucms vulnerability CVSS: 0 14 Nov 2022, 20:15 UTC

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

CVE-2022-41500 eyoucms vulnerability CVSS: 0 18 Oct 2022, 23:15 UTC

EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.

CVE-2022-36225 eyoucms vulnerability CVSS: 0 19 Aug 2022, 17:15 UTC

EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

CVE-2022-35509 eyoucms vulnerability CVSS: 0 10 Aug 2022, 20:15 UTC

An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive information.

CVE-2022-33122 eyoucms vulnerability CVSS: 3.5 24 Jun 2022, 21:15 UTC

A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.

CVE-2022-26273 eyoucms vulnerability CVSS: 7.5 28 Mar 2022, 02:15 UTC

EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

CVE-2022-26279 eyoucms vulnerability CVSS: 7.5 24 Mar 2022, 22:15 UTC

EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

CVE-2021-42194 eyoucms vulnerability CVSS: 6.5 20 Mar 2022, 22:15 UTC

The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

CVE-2021-46255 eyoucms vulnerability CVSS: 5.5 14 Jan 2022, 03:15 UTC

eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

CVE-2020-24000 eyoucms vulnerability CVSS: 7.5 03 Nov 2021, 17:15 UTC

SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

CVE-2021-39501 eyoucms vulnerability CVSS: 5.8 07 Sep 2021, 21:15 UTC

EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

CVE-2021-39500 eyoucms vulnerability CVSS: 5.0 07 Sep 2021, 21:15 UTC

Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.

CVE-2021-39499 eyoucms vulnerability CVSS: 4.3 07 Sep 2021, 20:15 UTC

A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.

CVE-2021-39497 eyoucms vulnerability CVSS: 7.5 07 Sep 2021, 20:15 UTC

eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

CVE-2021-39496 eyoucms vulnerability CVSS: 3.5 07 Sep 2021, 20:15 UTC

Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.

CVE-2020-20645 eyoucms vulnerability CVSS: 3.5 19 Aug 2021, 19:15 UTC

Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.

CVE-2020-20642 eyoucms vulnerability CVSS: 6.8 19 Aug 2021, 19:15 UTC

Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.

CVE-2020-19669 eyoucms vulnerability CVSS: 6.8 18 Aug 2021, 19:15 UTC

Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.

CVE-2020-28146 eyoucms vulnerability CVSS: 4.3 18 Aug 2021, 17:15 UTC

Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

CVE-2020-21930 eyoucms vulnerability CVSS: 3.5 10 Aug 2021, 22:15 UTC

A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.

CVE-2020-21929 eyoucms vulnerability CVSS: 3.5 10 Aug 2021, 22:15 UTC

A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.

CVE-2020-18129 eyoucms vulnerability CVSS: 6.8 22 Oct 2020, 21:15 UTC

A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

CVE-2019-17430 eyoucms vulnerability CVSS: 4.3 10 Oct 2019, 12:10 UTC

EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.