VYPR

Seacms

by Seacms

CVEs (116)

  • CVE-2023-46010CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

  • CVE-2023-44171CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

  • CVE-2023-44170CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

  • CVE-2023-44169CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2023-43216CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

  • CVE-2021-39426CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

  • CVE-2022-43256CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

  • CVE-2022-23878CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

  • CVE-2021-37358CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

  • CVE-2020-21378CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

  • CVE-2018-16822CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.

  • CVE-2018-16445CriSep 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.

  • CVE-2024-54880CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

  • CVE-2024-54879CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

  • CVE-2024-31611CriJun 10, 2024
    risk 0.59cvss 9.1epss 0.01

    SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

  • CVE-2018-16444CriSep 4, 2018
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.

  • CVE-2025-25515HigFeb 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.

  • CVE-2024-50808HigNov 8, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.

Page 2 of 6