Seacms
by Seacms
CVEs (116)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17062 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. | ||
| CVE-2018-14517 | Med | 0.40 | 6.1 | 0.01 | Jul 23, 2018 | SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields. | ||
| CVE-2018-11583 | Med | 0.40 | 6.1 | 0.01 | May 31, 2018 | SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter. | ||
| CVE-2025-25799 | Med | 0.39 | 6.0 | 0.00 | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php. | ||
| CVE-2025-50592 | Med | 0.35 | 5.4 | 0.00 | Aug 5, 2025 | Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player. | ||
| CVE-2024-44919 | Med | 0.35 | 5.4 | 0.00 | Aug 29, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter. | ||
| CVE-2023-50470 | Med | 0.35 | 5.4 | 0.00 | Dec 28, 2023 | A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37125 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-37124 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2023-2926 | Med | 0.35 | 5.4 | 0.01 | May 27, 2023 | A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated… | ||
| CVE-2018-19350 | Med | 0.35 | 5.4 | 0.01 | Nov 17, 2018 | In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. | ||
| CVE-2018-16821 | Med | 0.35 | 5.3 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. | ||
| CVE-2025-25800 | Med | 0.34 | 5.3 | 0.00 | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php. | ||
| CVE-2025-25813 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php. | ||
| CVE-2025-25802 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php. | ||
| CVE-2025-25797 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php. | ||
| CVE-2025-25796 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php. | ||
| CVE-2025-25794 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php. | ||
| CVE-2025-25793 | Med | 0.33 | 5.1 | 0.00 | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php. | ||
| CVE-2025-60449 | Med | 0.32 | 4.9 | 0.00 | Oct 3, 2025 | An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source… |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
- risk 0.40cvss 6.1epss 0.01
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
- risk 0.39cvss 6.0epss 0.00
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
- risk 0.35cvss 5.4epss 0.00
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.35cvss 5.4epss 0.01
A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated…
- risk 0.35cvss 5.4epss 0.01
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
- risk 0.35cvss 5.3epss 0.01
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
- risk 0.34cvss 5.3epss 0.00
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
- risk 0.33cvss 5.1epss 0.00
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
- risk 0.32cvss 4.9epss 0.00
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source…
Page 5 of 6