Eyoucms · Eyoucms · CVE-2026-13569
**Name of the Vulnerable Software and Affected Versions**
EyouCMS versions prior to 1.7.2
**Description**
A remote SQL injection exists in the API component due to improper processing of the `/index.php` file. An attacker can exploit this by manipulating the `click like` variable, allowing for unauthorized database queries.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/index.php` endpoint of the API component or avoid using the `click like` variable.