Seopanel
Products
1- 25 CVEs
Recent CVEs
25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-27461 | Hig | 0.57 | 8.8 | 0.04 | Aug 20, 2021 | A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function. | ||
| CVE-2017-10839 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2017 | SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | ||
| CVE-2021-28419 | Hig | 0.51 | 7.2 | 0.11 | Mar 18, 2021 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases. | ||
| CVE-2025-29452 | Hig | 0.49 | 7.6 | 0.00 | Apr 17, 2025 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component. | ||
| CVE-2025-29451 | Hig | 0.49 | 7.6 | 0.00 | Apr 17, 2025 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component. | ||
| CVE-2021-34117 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information. | ||
| CVE-2024-22643 | Med | 0.42 | 6.5 | 0.00 | Jan 30, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets. | ||
| CVE-2021-39413 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php,… | ||
| CVE-2021-3002 | Med | 0.40 | 6.1 | 0.04 | Jan 1, 2021 | Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter. | ||
| CVE-2017-10838 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2017 | Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2021-47872 | Hig | 0.39 | 7.1 | 0.00 | Jan 21, 2026 | SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database… | ||
| CVE-2020-35930 | Med | 0.35 | 5.4 | 0.01 | Dec 31, 2020 | Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI. | ||
| CVE-2024-22648 | Med | 0.34 | 5.3 | 0.01 | Jan 30, 2024 | A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment. | ||
| CVE-2024-22647 | Med | 0.34 | 5.3 | 0.01 | Jan 30, 2024 | An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames. | ||
| CVE-2024-22646 | Med | 0.34 | 5.3 | 0.01 | Jan 30, 2024 | An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system. | ||
| CVE-2021-28420 | Med | 0.34 | 4.8 | 0.02 | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter. | ||
| CVE-2021-28418 | Med | 0.34 | 4.8 | 0.02 | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. | ||
| CVE-2021-28417 | Med | 0.34 | 4.8 | 0.02 | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. | ||
| CVE-2021-29010 | Med | 0.31 | 4.8 | 0.01 | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter. | ||
| CVE-2021-29009 | Med | 0.31 | 4.8 | 0.01 | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter. |
- risk 0.57cvss 8.8epss 0.04
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.51cvss 7.2epss 0.11
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
- risk 0.49cvss 7.6epss 0.00
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
- risk 0.49cvss 7.6epss 0.00
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
- risk 0.49cvss 7.5epss 0.01
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
- risk 0.42cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.
- risk 0.40cvss 6.1epss 0.01
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php,…
- risk 0.40cvss 6.1epss 0.04
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.39cvss 7.1epss 0.00
SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database…
- risk 0.35cvss 5.4epss 0.01
Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.
- risk 0.34cvss 5.3epss 0.01
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.
- risk 0.34cvss 5.3epss 0.01
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
- risk 0.34cvss 5.3epss 0.01
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
- risk 0.34cvss 4.8epss 0.02
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
- risk 0.34cvss 4.8epss 0.02
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
- risk 0.34cvss 4.8epss 0.02
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
- risk 0.31cvss 4.8epss 0.01
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.
- risk 0.31cvss 4.8epss 0.01
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.