Vulnerabilities > Eyoucms > Low

DATE CVE VULNERABILITY TITLE RISK
2022-06-24 CVE-2022-33122 Cross-site Scripting vulnerability in Eyoucms 1.5.6
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.
network
eyoucms CWE-79
3.5
2021-09-07 CVE-2021-39496 Cross-site Scripting vulnerability in Eyoucms 1.5.4
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.
network
eyoucms CWE-79
3.5
2021-08-19 CVE-2020-20645 Cross-site Scripting vulnerability in Eyoucms 1.3.6
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
network
eyoucms CWE-79
3.5
2021-08-10 CVE-2020-21930 Cross-site Scripting vulnerability in Eyoucms 1.4.1
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
network
eyoucms CWE-79
3.5
2021-08-10 CVE-2020-21929 Cross-site Scripting vulnerability in Eyoucms 1.4.1
A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
network
eyoucms CWE-79
3.5