Eyoucms is a content-management system that, despite its narrow product footprint, has drawn a prominent presence in the vulnerability landscape. The system's vulnerabilities cluster around web-application layer weaknesses endemic to dynamic content platforms: cross-site scripting, cross-site request forgery, unsafe file upload handling, and insecure deserialization patterns all recur across its disclosures. These classes reflect common risks in user-input handling and session management within templating and file-serving contexts, and the vendor's vulnerability profile demonstrates a moderate tendency toward public exploit availability. Defenders deploying this platform should prioritize input sanitization controls, upload restrictions, and session-isolation measures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eyoucms over time
Signals from CVEs in this vendor scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1107CRITICAL A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manip | Jan 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2023-37645MEDIUM eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | Jul 20, 2023 | 5.3 | 34 | NO | YES |
CVE-2021-39501MEDIUM EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function. | Sep 7, 2021 | 6.1 | 32 | NO | YES |
CVE-2021-39497CRITICAL eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function. | Sep 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-26273CRITICAL EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities. | Mar 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-26279CRITICAL EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata. | Mar 24, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-24000CRITICAL SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. | Nov 3, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-42286CRITICAL There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malic | Mar 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-15375HIGH A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-22927MEDIUM Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | Feb 1, 2024 | 6.1 | 28 | NO | YES |
Signals from CVEs in this vendor scope (75 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eyoucms.
Media articles that mention a CVE ID that affects a product developed by Eyoucms — matched by CVE ID, not by vendor name.