VYPR

Seacms

by Seacms

CVEs (125)

  • CVE-2018-16446HigSep 4, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.

  • CVE-2026-85138HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-85137HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-82600HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-82598HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-15002HigDec 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2024-44916HigAug 30, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

  • CVE-2023-44847HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

  • CVE-2022-48093HigFeb 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.

  • CVE-2022-28076HigMay 4, 2022
    risk 0.47cvss 7.2epss 0.02

    Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

  • CVE-2018-19349HigNov 17, 2018
    risk 0.47cvss 7.2epss 0.01

    In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

  • CVE-2018-16343HigSep 2, 2018
    risk 0.47cvss 7.2epss 0.02

    SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.

  • CVE-2017-17561HigDec 12, 2017
    risk 0.47cvss 7.2epss 0.01

    SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

  • CVE-2024-42598MedAug 20, 2024
    risk 0.44cvss 6.7epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2024-40570MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.

  • CVE-2025-25514MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

  • CVE-2024-39036MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.01

    SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

  • CVE-2020-28846MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.

  • CVE-2024-6416MedJun 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to…

  • CVE-2020-36932MedJan 25, 2026
    risk 0.40cvss 6.1epss 0.00

    SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

Page 4 of 7