Seacms
by Seacms
CVEs (125)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46010 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | ||
| CVE-2023-44172 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php. | ||
| CVE-2023-44171 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php. | ||
| CVE-2023-44170 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php. | ||
| CVE-2023-44169 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php. | ||
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2023-43216 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. | ||
| CVE-2021-39426 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2022 | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set. | ||
| CVE-2022-43256 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. | ||
| CVE-2022-23878 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | ||
| CVE-2021-37358 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2021 | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=". | ||
| CVE-2020-21378 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php. | ||
| CVE-2018-16822 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. | ||
| CVE-2018-16445 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request. | ||
| CVE-2024-54880 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk. | ||
| CVE-2024-54879 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely. | ||
| CVE-2024-31611 | Cri | 0.59 | 9.1 | 0.01 | Jun 10, 2024 | SeaCMS 12.9 has a file deletion vulnerability via admin_template.php. | ||
| CVE-2018-16444 | Cri | 0.59 | 9.1 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter. | ||
| CVE-2026-79423 | Hig | 0.57 | 8.8 | 0.01 | Sep 4, 2026 | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | ||
| CVE-2025-25515 | Hig | 0.57 | 8.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. |
- risk 0.64cvss 9.8epss 0.01
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
- risk 0.64cvss 9.8epss 0.01
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
- risk 0.64cvss 9.8epss 0.02
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
- risk 0.59cvss 9.1epss 0.01
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
- risk 0.57cvss 8.8epss 0.01
An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.
- risk 0.57cvss 8.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
Page 2 of 7