VYPR

Vendor CVEs

Seacms

All CVEs

116 total · sorted by risk
  • CVE-2019-8418HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.

  • CVE-2018-14910HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF.

  • CVE-2018-14421HigJul 20, 2018
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.

  • CVE-2018-13445HigJul 8, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add.

  • CVE-2018-13444HigJul 8, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.

  • CVE-2023-44848HigOct 10, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.

  • CVE-2024-44720HigSep 9, 2024
    risk 0.49cvss 7.5epss 0.01

    SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

  • CVE-2024-39027HigJul 5, 2024
    risk 0.49cvss 7.5epss 0.00

    SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.

  • CVE-2018-17365HigSep 26, 2018
    risk 0.49cvss 7.5epss 0.02

    SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.

  • CVE-2018-16446HigSep 4, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.

  • CVE-2025-15002HigDec 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2024-44916HigAug 30, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

  • CVE-2023-44847HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

  • CVE-2022-48093HigFeb 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.

  • CVE-2022-28076HigMay 4, 2022
    risk 0.47cvss 7.2epss 0.02

    Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

  • CVE-2018-19349HigNov 17, 2018
    risk 0.47cvss 7.2epss 0.01

    In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

  • CVE-2018-16343HigSep 2, 2018
    risk 0.47cvss 7.2epss 0.03

    SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.

  • CVE-2017-17561HigDec 12, 2017
    risk 0.47cvss 7.2epss 0.01

    SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

  • CVE-2024-42598MedAug 20, 2024
    risk 0.44cvss 6.7epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2024-40570MedJun 17, 2025
    risk 0.42cvss 6.5epss 0.00

    SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.

  • CVE-2025-25514MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

  • CVE-2024-39036MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.01

    SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

  • CVE-2020-28846MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.

  • CVE-2024-6416MedJun 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to…

  • CVE-2020-36932MedJan 25, 2026
    risk 0.40cvss 6.1epss 0.00

    SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

  • CVE-2024-44920MedSep 3, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.

  • CVE-2024-44683MedAug 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

  • CVE-2021-29313MedAug 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,

  • CVE-2020-26642MedMay 28, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.

  • CVE-2018-17321MedSep 22, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.

  • CVE-2018-17062MedSep 16, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.

  • CVE-2018-14517MedJul 23, 2018
    risk 0.40cvss 6.1epss 0.01

    SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.

  • CVE-2018-11583MedMay 31, 2018
    risk 0.40cvss 6.1epss 0.01

    SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.

  • CVE-2025-25799MedFeb 26, 2025
    risk 0.39cvss 6.0epss 0.00

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

  • CVE-2025-50592MedAug 5, 2025
    risk 0.35cvss 5.4epss 0.00

    Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.

  • CVE-2024-44919MedAug 29, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.

  • CVE-2023-50470MedDec 28, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37125MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-37124MedJul 6, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-2926MedMay 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated…

  • CVE-2018-19350MedNov 17, 2018
    risk 0.35cvss 5.4epss 0.01

    In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.

  • CVE-2018-16821MedSep 21, 2018
    risk 0.35cvss 5.3epss 0.01

    SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.

  • CVE-2025-25800MedFeb 26, 2025
    risk 0.34cvss 5.3epss 0.00

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.

  • CVE-2025-25813MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

  • CVE-2025-25802MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

  • CVE-2025-25797MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

  • CVE-2025-25796MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

  • CVE-2025-25794MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

  • CVE-2025-25793MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

  • CVE-2025-60449MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source…