Vendor CVEs
Seacms
All CVEs
116 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27336 | Cri | 0.65 | 9.8 | 0.21 | Apr 27, 2022 | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. | ||
| CVE-2025-44073 | Cri | 0.64 | 9.8 | 0.00 | May 6, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. | ||
| CVE-2025-44074 | Cri | 0.64 | 9.8 | 0.00 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php. | ||
| CVE-2025-44072 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php. | ||
| CVE-2025-44071 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request. | ||
| CVE-2025-29647 | Cri | 0.64 | 9.8 | 0.00 | Apr 3, 2025 | SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php. | ||
| CVE-2025-25521 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | ||
| CVE-2025-25520 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | ||
| CVE-2025-25519 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | ||
| CVE-2025-25517 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | ||
| CVE-2025-25516 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | ||
| CVE-2025-22974 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | ||
| CVE-2025-25513 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php. | ||
| CVE-2024-55461 | Cri | 0.64 | 9.8 | 0.01 | Dec 18, 2024 | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). | ||
| CVE-2024-46640 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method. | ||
| CVE-2024-44721 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2024 | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. | ||
| CVE-2024-44921 | Cri | 0.64 | 9.8 | 0.01 | Sep 3, 2024 | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del. | ||
| CVE-2024-41444 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so. | ||
| CVE-2024-39028 | Cri | 0.64 | 9.8 | 0.01 | Jul 5, 2024 | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. | ||
| CVE-2024-29275 | Cri | 0.64 | 9.8 | 0.05 | Mar 22, 2024 | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. | ||
| CVE-2023-46010 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | ||
| CVE-2023-44172 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php. | ||
| CVE-2023-44171 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php. | ||
| CVE-2023-44170 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php. | ||
| CVE-2023-44169 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php. | ||
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2023-43216 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. | ||
| CVE-2021-39426 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2022 | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set. | ||
| CVE-2022-43256 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. | ||
| CVE-2022-23878 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | ||
| CVE-2021-37358 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2021 | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=". | ||
| CVE-2020-21378 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php. | ||
| CVE-2018-16822 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2018 | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. | ||
| CVE-2018-16445 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request. | ||
| CVE-2024-54880 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk. | ||
| CVE-2024-54879 | Cri | 0.59 | 9.1 | 0.01 | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely. | ||
| CVE-2024-31611 | Cri | 0.59 | 9.1 | 0.01 | Jun 10, 2024 | SeaCMS 12.9 has a file deletion vulnerability via admin_template.php. | ||
| CVE-2018-16444 | Cri | 0.59 | 9.1 | 0.01 | Sep 4, 2018 | An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter. | ||
| CVE-2025-25515 | Hig | 0.57 | 8.8 | 0.00 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | ||
| CVE-2024-50808 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2024 | SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php. | ||
| CVE-2024-42599 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the… | ||
| CVE-2024-40522 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute… | ||
| CVE-2024-40521 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers… | ||
| CVE-2024-40520 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the… | ||
| CVE-2024-40519 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary… | ||
| CVE-2024-40518 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary… | ||
| CVE-2024-30565 | Hig | 0.57 | 8.8 | 0.02 | Apr 4, 2024 | An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php. | ||
| CVE-2023-46987 | Hig | 0.57 | 8.8 | 0.01 | Dec 28, 2023 | SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php. | ||
| CVE-2023-44846 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component. | ||
| CVE-2023-43278 | Hig | 0.57 | 8.8 | 0.00 | Sep 25, 2023 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account. |
- risk 0.65cvss 9.8epss 0.21
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
- risk 0.64cvss 9.8epss 0.01
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
- risk 0.64cvss 9.8epss 0.01
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
- risk 0.64cvss 9.8epss 0.01
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
- risk 0.64cvss 9.8epss 0.02
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
- risk 0.59cvss 9.1epss 0.01
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
- risk 0.59cvss 9.1epss 0.01
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
- risk 0.57cvss 8.8epss 0.00
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
- risk 0.57cvss 8.8epss 0.01
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
- risk 0.57cvss 8.8epss 0.01
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…
- risk 0.57cvss 8.8epss 0.01
There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute…
- risk 0.57cvss 8.8epss 0.01
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers…
- risk 0.57cvss 8.8epss 0.01
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the…
- risk 0.57cvss 8.8epss 0.01
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary…
- risk 0.57cvss 8.8epss 0.01
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary…
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
- risk 0.57cvss 8.8epss 0.01
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
- risk 0.57cvss 8.8epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
Page 1 of 3