VYPR

Seacms

by Seacms

CVEs (116)

  • CVE-2018-17062MedSep 16, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.

  • CVE-2018-14517MedJul 23, 2018
    risk 0.40cvss 6.1epss 0.01

    SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.

  • CVE-2018-11583MedMay 31, 2018
    risk 0.40cvss 6.1epss 0.01

    SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.

  • CVE-2025-25799MedFeb 26, 2025
    risk 0.39cvss 6.0epss 0.00

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

  • CVE-2025-50592MedAug 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.

  • CVE-2024-44919MedAug 29, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.

  • CVE-2023-50470MedDec 28, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37125MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37124MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-2926MedMay 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated…

  • CVE-2018-19350MedNov 17, 2018
    risk 0.35cvss 5.4epss 0.01

    In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.

  • CVE-2018-16821MedSep 21, 2018
    risk 0.35cvss 5.3epss 0.01

    SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.

  • CVE-2025-25800MedFeb 26, 2025
    risk 0.34cvss 5.3epss 0.00

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.

  • CVE-2025-25813MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

  • CVE-2025-25802MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

  • CVE-2025-25797MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

  • CVE-2025-25796MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

  • CVE-2025-25794MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

  • CVE-2025-25793MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

  • CVE-2025-60449MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source…

Page 5 of 6