Seacms
by Seacms
CVEs (125)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-44920 | Med | 0.40 | 6.1 | 0.00 | Sep 3, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter. | ||
| CVE-2024-44683 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2024 | Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. | ||
| CVE-2021-29313 | Med | 0.40 | 6.1 | 0.01 | Aug 17, 2021 | Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php, | ||
| CVE-2020-26642 | Med | 0.40 | 6.1 | 0.01 | May 28, 2021 | A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML. | ||
| CVE-2018-17321 | Med | 0.40 | 6.1 | 0.01 | Sep 22, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action. | ||
| CVE-2018-17062 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. | ||
| CVE-2018-14517 | Med | 0.40 | 6.1 | 0.01 | Jul 23, 2018 | SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields. | ||
| CVE-2018-11583 | Med | 0.40 | 6.1 | 0.01 | May 31, 2018 | SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter. | ||
| CVE-2025-25799 | Med | 0.39 | 6.0 | 0.00 | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php. | ||
| CVE-2026-82603 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The… | ||
| CVE-2026-82599 | Med | 0.35 | 5.4 | 0.00 | Aug 31, 2026 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the… | ||
| CVE-2025-50592 | Med | 0.35 | 5.4 | 0.00 | Aug 5, 2025 | Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player. | ||
| CVE-2024-44919 | Med | 0.35 | 5.4 | 0.00 | Aug 29, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter. | ||
| CVE-2023-50470 | Med | 0.35 | 5.4 | 0.00 | Dec 28, 2023 | A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37125 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37124 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-2926 | Med | 0.35 | 5.4 | 0.01 | May 27, 2023 | A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated… | ||
| CVE-2018-19350 | Med | 0.35 | 5.4 | 0.01 | Nov 17, 2018 | In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. | ||
| CVE-2018-16821 | Med | 0.35 | 5.3 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. | ||
| CVE-2026-82602 | Med | 0.34 | 5.3 | 0.00 | Aug 31, 2026 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
- risk 0.40cvss 6.1epss 0.00
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
- risk 0.39cvss 6.0epss 0.00
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
- risk 0.35cvss 5.4epss 0.00
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The…
- risk 0.35cvss 5.4epss 0.00
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the…
- risk 0.35cvss 5.4epss 0.00
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated…
- risk 0.35cvss 5.4epss 0.01
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
- risk 0.35cvss 5.3epss 0.01
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
- risk 0.34cvss 5.3epss 0.00
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Page 5 of 7