Seacms
by Seacms
CVEs (116)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46010 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | ||
| CVE-2023-44172 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php. | ||
| CVE-2023-44171 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php. | ||
| CVE-2023-44170 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php. | ||
| CVE-2023-44169 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php. | ||
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2023-43216 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. | ||
| CVE-2021-39426 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2022 | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set. | ||
| CVE-2022-43256 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. | ||
| CVE-2022-23878 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | ||
| CVE-2021-37358 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2021 | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=". | ||
| CVE-2020-21378 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php. | ||
| CVE-2018-16822 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. | ||
| CVE-2018-16445 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request. | ||
| CVE-2024-54880 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk. | ||
| CVE-2024-54879 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely. | ||
| CVE-2024-31611 | Cri | 0.59 | 9.1 | 0.01 | Jun 10, 2024 | SeaCMS 12.9 has a file deletion vulnerability via admin_template.php. | ||
| CVE-2018-16444 | Cri | 0.59 | 9.1 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter. | ||
| CVE-2025-25515 | Hig | 0.57 | 8.8 | 0.00 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | ||
| CVE-2024-50808 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2024 | SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php. |
- risk 0.64cvss 9.8epss 0.01
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
- risk 0.64cvss 9.8epss 0.01
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
- risk 0.64cvss 9.8epss 0.02
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
- risk 0.59cvss 9.1epss 0.01
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
- risk 0.57cvss 8.8epss 0.00
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
- risk 0.57cvss 8.8epss 0.01
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
Page 2 of 6