Vulnerabilities > Eyoucms

DATE CVE VULNERABILITY TITLE RISK
2021-08-10 CVE-2020-21930 Cross-site Scripting vulnerability in Eyoucms 1.4.1
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
network
low complexity
eyoucms CWE-79
5.4
2020-10-22 CVE-2020-18129 Cross-Site Request Forgery (CSRF) vulnerability in Eyoucms 1.2.7
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
network
low complexity
eyoucms CWE-352
8.8
2019-10-10 CVE-2019-17430 Cross-site Scripting vulnerability in Eyoucms
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
network
low complexity
eyoucms CWE-79
6.1