SQL Injection Vulnerability in weng-xianhu EyouCMS by Weng-Xianhu
CVE-2026-13569
Key Information:
- Vendor
Weng-xianhu
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13569?
A security flaw has been identified in the weng-xianhu EyouCMS, specifically in versions up to 1.7.1. The vulnerability resides in the /index.php file associated with the API component, where improper handling of the 'click_like' argument can lead to SQL injection attacks. This vulnerability allows remote execution of the exploit, posing significant risks to user data and system integrity. The issue has been publicly disclosed, and while the project maintainers were alerted early on, no resolution has been communicated, making it crucial for users to assess their exposure and take preventive measures.
Affected Version(s)
EyouCMS 1.7.0
EyouCMS 1.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
