VYPR

Seacms 13.6 Security Advisories

by T Chachamaru

CVEs (2)

  • CVE-2026-85138HigSep 3, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-85137HigSep 3, 2026
    risk 0.47cvss 7.3epss

    A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…