CVE-2026-6561Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-19: 3Technical Details · 2026-04-19: 104-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6561 A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a man… https://www.cve.org/CVERecord?id=CVE-2026-6561 ----- Traducción: CVE-2026-6561 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6561 for EyouCMS affecting the edit_adminlogo function, but offers no further details on exploitation, patching, or technical specifics.

    0000034
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6561 A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a man… https://www.cve.org/CVERecord?id=CVE-2026-6561

    Post summary

    The post announces CVE‑2026‑6561 in EyouCMS and notes the affected function, but it provides no details on exploitation, patches, or mitigation.

    00000361
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6561 Unrestricted File Upload in EyouCMS Up to 1.7.1 Via Filename Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6561

    Post summary

    The post announces a newly disclosed vulnerability—Unrestricted File Upload in EyouCMS up to 1.7.1 via filename manipulation—without providing a PoC, exploit code, or any mention of active exploitation, patches, or false positives.

    0000052
    4.0K followersView on X

Explore more