Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eyoucms

First CVE: Oct 10, 2019Active for: 7 yearsTotal CVEs: 75
35.9
VTI Score
Medium

Eyoucms is a content-management system that, despite its narrow product footprint, has drawn a prominent presence in the vulnerability landscape. The system's vulnerabilities cluster around web-application layer weaknesses endemic to dynamic content platforms: cross-site scripting, cross-site request forgery, unsafe file upload handling, and insecure deserialization patterns all recur across its disclosures. These classes reflect common risks in user-input handling and session management within templating and file-serving contexts, and the vendor's vulnerability profile demonstrates a moderate tendency toward public exploit availability. Defenders deploying this platform should prioritize input sanitization controls, upload restrictions, and session-isolation measures; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
75
Total CVEs
More Total CVEs than 99% of tracked vendors
9.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Eyoucms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2019
6 years ago
Most Recent CVE
Jan 18, 2026
187 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-1107CRITICAL
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manip
Jan 18, 20269.834NONO
CVE-2023-37645MEDIUM
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
Jul 20, 20235.334NOYES
CVE-2021-39501MEDIUM
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
Sep 7, 20216.132NOYES
CVE-2021-39497CRITICAL
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
Sep 7, 20219.831NONO
CVE-2022-26273CRITICAL
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
Mar 28, 20229.830NONO
CVE-2022-26279CRITICAL
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
Mar 24, 20229.830NONO
CVE-2020-24000CRITICAL
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
Nov 3, 20219.830NONO
CVE-2023-42286CRITICAL
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malic
Mar 14, 20249.829NONO
CVE-2025-15375HIGH
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler.
Dec 31, 20258.828NONO
CVE-2024-22927MEDIUM
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
Feb 1, 20246.128NOYES
View all 75 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products75 CVEs
71%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network75 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low75 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (24.0%)
Unknown0 (0.0%)
Required57 (76.0%)
Privileges Required
Low27 (36.0%)
High8 (10.7%)
None40 (53.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
5.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eyoucms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eyoucms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eyoucms's Products

View all 2 CNAs →

Top CWEs