Skip to content
Noroxi

Seacms records

114 published records for vendor seacms.

All records

114 records
  • Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

    CriticalCVSS 9.8No exploitEPSS 21%

    seacms · seacmsApr 27, 2022

  • SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive i

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    seacms · seacmsMar 22, 2024

  • SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=chec

    CriticalCVSS 9.8No exploitEPSS 2%

    seacms · seacmsAug 18, 2021

  • seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    seacms · seacmsMar 2, 2022

  • SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    seacms · seacmsDec 21, 2020

  • SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 21, 2018

  • An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsOct 25, 2023

  • SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsDec 18, 2024

  • An issue was discovered in SeaCMS through 6.61.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 4, 2018

  • An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsJul 5, 2024

  • SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsMay 5, 2025

  • SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 20, 2024

  • CVE-2023-0960
    39Monitor

    SeaCMS Picture Management config.ftp.php deserialization

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsFeb 22, 2023

  • SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 27, 2023

  • SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsNov 16, 2022

  • An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 para

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsDec 15, 2022

  • SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter i

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsFeb 24, 2025

  • SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 3, 2024

  • SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsSep 9, 2024

  • SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    seacms · seacmsApr 3, 2025