CVE-2023-42286: Eyoucms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.

Affected products

  • Eyoucms Eyoucms: version 1.6.4 only

Published 2024-03-14. Last modified 2026-06-17.