Seacms
by Seacms
CVEs (116)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15002 | Hig | 0.47 | 7.3 | 0.00 | Dec 21, 2025 | A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has… | ||
| CVE-2024-44916 | Hig | 0.47 | 7.2 | 0.01 | Aug 30, 2024 | Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution. | ||
| CVE-2023-44847 | Hig | 0.47 | 7.2 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component. | ||
| CVE-2022-48093 | Hig | 0.47 | 7.2 | 0.01 | Feb 1, 2023 | Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php. | ||
| CVE-2022-28076 | Hig | 0.47 | 7.2 | 0.02 | May 4, 2022 | Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings. | ||
| CVE-2018-19349 | Hig | 0.47 | 7.2 | 0.01 | Nov 17, 2018 | In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php. | ||
| CVE-2018-16343 | Hig | 0.47 | 7.2 | 0.03 | Sep 2, 2018 | SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS. | ||
| CVE-2017-17561 | Hig | 0.47 | 7.2 | 0.01 | Dec 12, 2017 | SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php. | ||
| CVE-2024-42598 | Med | 0.44 | 6.7 | 0.01 | Aug 20, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the… | ||
| CVE-2024-40570 | Med | 0.42 | 6.5 | 0.00 | Jun 17, 2025 | SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component. | ||
| CVE-2025-25514 | Med | 0.42 | 6.5 | 0.00 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. | ||
| CVE-2024-39036 | Med | 0.42 | 6.5 | 0.01 | Jul 16, 2024 | SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php. | ||
| CVE-2020-28846 | Med | 0.42 | 6.5 | 0.00 | Aug 17, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account. | ||
| CVE-2024-6416 | Med | 0.41 | 6.3 | 0.01 | Jun 30, 2024 | A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to… | ||
| CVE-2020-36932 | Med | 0.40 | 6.1 | 0.00 | Jan 25, 2026 | SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded. | ||
| CVE-2024-44920 | Med | 0.40 | 6.1 | 0.00 | Sep 3, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter. | ||
| CVE-2024-44683 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2024 | Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. | ||
| CVE-2021-29313 | Med | 0.40 | 6.1 | 0.01 | Aug 17, 2021 | Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php, | ||
| CVE-2020-26642 | Med | 0.40 | 6.1 | 0.01 | May 28, 2021 | A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML. | ||
| CVE-2018-17321 | Med | 0.40 | 6.1 | 0.01 | Sep 22, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action. |
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has…
- risk 0.47cvss 7.2epss 0.01
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
- risk 0.47cvss 7.2epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
- risk 0.47cvss 7.2epss 0.01
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
- risk 0.47cvss 7.2epss 0.02
Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
- risk 0.47cvss 7.2epss 0.01
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
- risk 0.47cvss 7.2epss 0.03
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
- risk 0.47cvss 7.2epss 0.01
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.
- risk 0.44cvss 6.7epss 0.01
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…
- risk 0.42cvss 6.5epss 0.00
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.
- risk 0.42cvss 6.5epss 0.00
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
- risk 0.42cvss 6.5epss 0.01
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
- risk 0.42cvss 6.5epss 0.00
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to…
- risk 0.40cvss 6.1epss 0.00
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
- risk 0.40cvss 6.1epss 0.00
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
Page 4 of 6