VYPR

Seacms

by Seacms

CVEs (125)

  • CVE-2023-46010CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

  • CVE-2023-44171CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

  • CVE-2023-44170CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

  • CVE-2023-44169CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2023-43216CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

  • CVE-2021-39426CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

  • CVE-2022-43256CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

  • CVE-2022-23878CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

  • CVE-2021-37358CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

  • CVE-2020-21378CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

  • CVE-2018-16822CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.

  • CVE-2018-16445CriSep 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.

  • CVE-2024-54880CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

  • CVE-2024-54879CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

  • CVE-2024-31611CriJun 10, 2024
    risk 0.59cvss 9.1epss 0.01

    SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

  • CVE-2018-16444CriSep 4, 2018
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.

  • CVE-2026-79423HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-25515HigFeb 25, 2025
    risk 0.57cvss 8.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.

Page 2 of 7