CVE-2025-15375: Eyoucms
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be launched remotely. The exploit has been published and may be used. The vendor is "[a]cknowledging the existence of the vulnerability, we have completed the fix and will release a new version, v1.7.8".
Affected products
- Eyoucms Eyoucms: before 1.7.8 (fixed in 1.7.8)
Published 2025-12-31. Last modified 2026-06-17.