Seacms
by Seacms
CVEs (116)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27336 | Cri | 0.65 | 9.8 | 0.21 | Apr 27, 2022 | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. | ||
| CVE-2025-44073 | Cri | 0.64 | 9.8 | 0.00 | May 6, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. | ||
| CVE-2025-44074 | Cri | 0.64 | 9.8 | 0.00 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php. | ||
| CVE-2025-44072 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php. | ||
| CVE-2025-44071 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request. | ||
| CVE-2025-29647 | Cri | 0.64 | 9.8 | 0.00 | Apr 3, 2025 | SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php. | ||
| CVE-2025-25521 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | ||
| CVE-2025-25520 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | ||
| CVE-2025-25519 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | ||
| CVE-2025-25517 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | ||
| CVE-2025-25516 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | ||
| CVE-2025-22974 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | ||
| CVE-2025-25513 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php. | ||
| CVE-2024-55461 | Cri | 0.64 | 9.8 | 0.01 | Dec 18, 2024 | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). | ||
| CVE-2024-46640 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method. | ||
| CVE-2024-44721 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2024 | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. | ||
| CVE-2024-44921 | Cri | 0.64 | 9.8 | 0.01 | Sep 3, 2024 | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del. | ||
| CVE-2024-41444 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so. | ||
| CVE-2024-39028 | Cri | 0.64 | 9.8 | 0.01 | Jul 5, 2024 | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. | ||
| CVE-2024-29275 | Cri | 0.64 | 9.8 | 0.05 | Mar 22, 2024 | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. |
- risk 0.65cvss 9.8epss 0.21
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
- risk 0.64cvss 9.8epss 0.01
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
Page 1 of 6