CVE-2025-65868

HIGH WAF: High
CVSS 7.5 Published: 2025-12-03
CWE-611

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
eyoucmseyoucms1.7.1

References

  • github.com (Exploit, Issue Tracking, Vendor Advisory)
Back to CVE Database