Skip to content
EyouCMS Vulnerability CVE-2025-15373 and Zero-Day Exploit CVE-2025-20393

EyouCMS Vulnerability CVE-2025-15373 and Zero-Day Exploit CVE-2025-20393

First seen 9 Jan 2026, 19:00 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A security vulnerability (CVE-2025-15373) has been found in EyouCMS versions up to 1.7.7, allowing remote server-side request forgery. The vendor has acknowledged the issue and plans to release a fix in version 1.7.8. Additionally, a separate unpatched zero-day vulnerability (CVE-2025-20393) is being exploited, specifically affecting deployments with the Spam Quarantine feature enabled.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-15373 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed