EyouCMS Vulnerability CVE-2025-15373 and Zero-Day Exploit CVE-2025-20393

EyouCMS Vulnerability CVE-2025-15373 and Zero-Day Exploit CVE-2025-20393

First seen 9 Jan 2026, 19:00 UTC ArcticwolfNvd.Nist 26.2

Article Content

Browse articles
ThreatCluster

A security vulnerability (CVE-2025-15373) has been found in EyouCMS versions up to 1.7.7, allowing remote server-side request forgery. The vendor has acknowledged the issue and plans to release a fix in version 1.7.8. Additionally, a separate unpatched zero-day vulnerability (CVE-2025-20393) is being exploited, specifically affecting deployments with the Spam Quarantine feature enabled.