Arcticwolf
EyouCMS Vulnerability CVE-2025-15373 and Zero-Day Exploit CVE-2025-20393
First seen 9 Jan 2026, 19:00 UTC
•
•26.2
Export
Article Content
Browse articles
A security vulnerability (CVE-2025-15373) has been found in EyouCMS versions up to 1.7.7, allowing remote server-side request forgery. The vendor has acknowledged the issue and plans to release a fix in version 1.7.8. Additionally, a separate unpatched zero-day vulnerability (CVE-2025-20393) is being exploited, specifically affecting deployments with the Spam Quarantine feature enabled.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Critical Vulnerabilities in Fluentd Enable Remote Code Execution and SSRF
Apache Syncope Vulnerabilities Enable Remote Code Execution and Privilege Escalation
July 2026 Security Update: Record CVEs and Critical Vulnerabilities