Seacms records
114 published records for vendor seacms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 15
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')25
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-94 Improper Control of Generation of Code ('Code Injection')18
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
114 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2022-27336No exploit | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.seacms · seacms | Critical9.8 | — | 20.5% | Apr 27, 2022 |
40Plan | CVE-2024-29275Proof of concept | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive iseacms · seacms · CWE-89 | Critical9.8 | — | 5.0% | Mar 22, 2024 |
40Plan | CVE-2021-37358No exploit | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checseacms · seacms · CWE-89 | Critical9.8 | — | 2.3% | Aug 18, 2021 |
40Plan | CVE-2022-23878No exploit | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.seacms · seacms | Critical9.8 | — | 2.2% | Mar 2, 2022 |
40Plan | CVE-2020-21378Proof of concept | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.seacms · seacms · CWE-89 | Critical9.8 | — | 2.1% | Dec 21, 2020 |
39Monitor | CVE-2023-44169No exploit | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.seacms · seacms · CWE-22 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
39Monitor | CVE-2023-44171No exploit | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.seacms · seacms · CWE-22 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
39Monitor | CVE-2023-43216No exploit | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.seacms · seacms · CWE-22 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
39Monitor | CVE-2023-44170No exploit | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.seacms · seacms · CWE-22 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
39Monitor | CVE-2023-44172No exploit | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.seacms · seacms · CWE-22 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
39Monitor | CVE-2018-16822No exploit | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.seacms · seacms · CWE-89 | Critical9.8 | — | 1.2% | Sep 21, 2018 |
39Monitor | CVE-2023-46010No exploit | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.seacms · seacms · CWE-94 | Critical9.8 | — | 1.2% | Oct 25, 2023 |
39Monitor | CVE-2024-55461No exploit | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().seacms · seacms · CWE-77 | Critical9.8 | — | 1.1% | Dec 18, 2024 |
39Monitor | CVE-2018-16445No exploit | An issue was discovered in SeaCMS through 6.61.seacms · seacms · CWE-89 | Critical9.8 | — | 1.1% | Sep 4, 2018 |
39Monitor | CVE-2024-39028No exploit | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.seacms · seacms · CWE-77 | Critical9.8 | — | 1.1% | Jul 5, 2024 |
39Monitor | CVE-2025-44071No exploit | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.seacms · seacms · CWE-94 | Critical9.8 | — | 1.0% | May 5, 2025 |
39Monitor | CVE-2024-46640No exploit | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.seacms · seacms · CWE-94 | Critical9.8 | — | 1.0% | Sep 20, 2024 |
39Monitor | CVE-2023-0960No exploit | SeaCMS Picture Management config.ftp.php deserializationseacms · seacms · CWE-502 | Critical9.8 | — | 1.0% | Feb 22, 2023 |
39Monitor | CVE-2023-43222No exploit | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.seacms · seacms · CWE-94 | Critical9.8 | — | 1.0% | Sep 27, 2023 |
39Monitor | CVE-2022-43256No exploit | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.seacms · seacms · CWE-89 | Critical9.8 | — | 0.9% | Nov 16, 2022 |
39Monitor | CVE-2021-39426No exploit | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 paraseacms · seacms · CWE-94 | Critical9.8 | — | 0.9% | Dec 15, 2022 |
39Monitor | CVE-2025-22974No exploit | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter iseacms · seacms · CWE-89 | Critical9.8 | — | 0.8% | Feb 24, 2025 |
39Monitor | CVE-2024-44921No exploit | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.seacms · seacms · CWE-89 | Critical9.8 | — | 0.6% | Sep 3, 2024 |
39Monitor | CVE-2024-44721No exploit | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.seacms · seacms · CWE-918 | Critical9.8 | — | 0.6% | Sep 9, 2024 |
39Monitor | CVE-2025-29647No exploit | SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.seacms · seacms · CWE-89 | Critical9.8 | — | 0.5% | Apr 3, 2025 |
- CVE-2022-2733645Plan
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CriticalCVSS 9.8No exploitEPSS 21%seacms · seacmsApr 27, 2022
- CVE-2024-2927540Plan
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive i
CriticalCVSS 9.8Proof of conceptEPSS 5%seacms · seacmsMar 22, 2024
- CVE-2021-3735840Plan
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=chec
CriticalCVSS 9.8No exploitEPSS 2%seacms · seacmsAug 18, 2021
- CVE-2022-2387840Plan
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CriticalCVSS 9.8No exploitEPSS 2%seacms · seacmsMar 2, 2022
- CVE-2020-2137840Plan
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
CriticalCVSS 9.8Proof of conceptEPSS 2%seacms · seacmsDec 21, 2020
- CVE-2023-4416939Monitor
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2023-4417139Monitor
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2023-4321639Monitor
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2023-4417039Monitor
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2023-4417239Monitor
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2018-1682239Monitor
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 21, 2018
- CVE-2023-4601039Monitor
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsOct 25, 2023
- CVE-2024-5546139Monitor
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsDec 18, 2024
- CVE-2018-1644539Monitor
An issue was discovered in SeaCMS through 6.61.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 4, 2018
- CVE-2024-3902839Monitor
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsJul 5, 2024
- CVE-2025-4407139Monitor
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsMay 5, 2025
- CVE-2024-4664039Monitor
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 20, 2024
- CVE-2023-096039Monitor
SeaCMS Picture Management config.ftp.php deserialization
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsFeb 22, 2023
- CVE-2023-4322239Monitor
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 27, 2023
- CVE-2022-4325639Monitor
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsNov 16, 2022
- CVE-2021-3942639Monitor
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 para
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsDec 15, 2022
- CVE-2025-2297439Monitor
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter i
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsFeb 24, 2025
- CVE-2024-4492139Monitor
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 3, 2024
- CVE-2024-4472139Monitor
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsSep 9, 2024
- CVE-2025-2964739Monitor
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CriticalCVSS 9.8No exploitEPSS 1%seacms · seacmsApr 3, 2025