VYPR

Vendor CVEs

Seacms

All CVEs

116 total · sorted by risk
  • CVE-2022-27336CriApr 27, 2022
    risk 0.65cvss 9.8epss 0.21

    Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

  • CVE-2025-44073CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.

  • CVE-2025-44074CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.

  • CVE-2025-44072CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.

  • CVE-2025-44071CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.

  • CVE-2025-29647CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.

  • CVE-2025-25521CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

  • CVE-2025-25520CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

  • CVE-2025-25519CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

  • CVE-2025-25517CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

  • CVE-2025-25516CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

  • CVE-2025-22974CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

  • CVE-2025-25513CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

  • CVE-2024-55461CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

  • CVE-2024-46640CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.

  • CVE-2024-44721CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

  • CVE-2024-44921CriSep 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

  • CVE-2024-41444CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.

  • CVE-2024-39028CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

  • CVE-2024-29275CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.

  • CVE-2023-46010CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

  • CVE-2023-44171CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

  • CVE-2023-44170CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

  • CVE-2023-44169CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2023-43216CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

  • CVE-2021-39426CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

  • CVE-2022-43256CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

  • CVE-2022-23878CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

  • CVE-2021-37358CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

  • CVE-2020-21378CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

  • CVE-2018-16822CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.

  • CVE-2018-16445CriSep 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.

  • CVE-2024-54880CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

  • CVE-2024-54879CriJan 6, 2025
    risk 0.59cvss 9.1epss 0.01

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

  • CVE-2024-31611CriJun 10, 2024
    risk 0.59cvss 9.1epss 0.01

    SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

  • CVE-2018-16444CriSep 4, 2018
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.

  • CVE-2025-25515HigFeb 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.

  • CVE-2024-50808HigNov 8, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.

  • CVE-2024-42599HigAug 22, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2024-40522HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute…

  • CVE-2024-40521HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers…

  • CVE-2024-40520HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the…

  • CVE-2024-40519HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary…

  • CVE-2024-40518HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary…

  • CVE-2024-30565HigApr 4, 2024
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

  • CVE-2023-46987HigDec 28, 2023
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.

  • CVE-2023-44846HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.

  • CVE-2023-43278HigSep 25, 2023
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.

Page 1 of 3