VYPR

Seacms

by Seacms

CVEs (116)

  • CVE-2025-15002HigDec 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2024-44916HigAug 30, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

  • CVE-2023-44847HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

  • CVE-2022-48093HigFeb 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.

  • CVE-2022-28076HigMay 4, 2022
    risk 0.47cvss 7.2epss 0.02

    Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

  • CVE-2018-19349HigNov 17, 2018
    risk 0.47cvss 7.2epss 0.01

    In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

  • CVE-2018-16343HigSep 2, 2018
    risk 0.47cvss 7.2epss 0.03

    SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.

  • CVE-2017-17561HigDec 12, 2017
    risk 0.47cvss 7.2epss 0.01

    SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

  • CVE-2024-42598MedAug 20, 2024
    risk 0.44cvss 6.7epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2024-40570MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.

  • CVE-2025-25514MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

  • CVE-2024-39036MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.01

    SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

  • CVE-2020-28846MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.

  • CVE-2024-6416MedJun 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to…

  • CVE-2020-36932MedJan 25, 2026
    risk 0.40cvss 6.1epss 0.00

    SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

  • CVE-2024-44920MedSep 3, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.

  • CVE-2024-44683MedAug 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

  • CVE-2021-29313MedAug 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,

  • CVE-2020-26642MedMay 28, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.

  • CVE-2018-17321MedSep 22, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.

Page 4 of 6