VYPR
Vendor

Seacms

Products
3
CVEs
116
Across products
119
Status
Private

Products

3

Recent CVEs

116
View all 116 CVEs →
  • CVE-2022-27336CriApr 27, 2022
    risk 0.65cvss 9.8epss 0.21

    Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

  • CVE-2025-44073CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.

  • CVE-2025-44074CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.

  • CVE-2025-44072CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.

  • CVE-2025-44071CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.

  • CVE-2025-29647CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.

  • CVE-2025-25521CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

  • CVE-2025-25520CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

  • CVE-2025-25519CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

  • CVE-2025-25517CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

  • CVE-2025-25516CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

  • CVE-2025-22974CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

  • CVE-2025-25513CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

  • CVE-2024-55461CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

  • CVE-2024-46640CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.

  • CVE-2024-44721CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

  • CVE-2024-44921CriSep 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

  • CVE-2024-41444CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.

  • CVE-2024-39028CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

  • CVE-2024-29275CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.