Sem CMS
Products
1- 61 CVEs
Recent CVEs
61| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-25686 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2025 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. | ||
| CVE-2024-46103 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | ||
| CVE-2024-30938 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | ||
| CVE-2024-31012 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2024 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file. | ||
| CVE-2024-25422 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component. | ||
| CVE-2023-50563 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. | ||
| CVE-2023-37647 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. | ||
| CVE-2020-18432 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2023 | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges. | ||
| CVE-2023-31707 | Cri | 0.64 | 9.8 | 0.01 | May 19, 2023 | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php. | ||
| CVE-2023-30090 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2021-38733 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | ||
| CVE-2021-38732 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | ||
| CVE-2021-38731 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | ||
| CVE-2021-38730 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | ||
| CVE-2021-38729 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | ||
| CVE-2021-38217 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. | ||
| CVE-2021-38737 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. | ||
| CVE-2021-38736 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. | ||
| CVE-2021-38734 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. | ||
| CVE-2020-18078 | Cri | 0.64 | 9.8 | 0.01 | Dec 17, 2021 | A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password. |
- risk 0.64cvss 9.8epss 0.00
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
- risk 0.64cvss 9.8epss 0.01
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
- risk 0.64cvss 9.8epss 0.01
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
- risk 0.64cvss 9.8epss 0.01
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.