VYPR

CMS

by Seacms

CVEs (2)

  • CVE-2024-29275CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.

  • CVE-2024-39027HigJul 5, 2024
    risk 0.49cvss 7.5epss 0.00

    SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.