sem-cms records
59 published records for vendor sem-cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')36
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
59 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-31012No exploit | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive informsem-cms · semcms · CWE-434 | Critical9.8 | — | 1.2% | Apr 3, 2024 |
39Monitor | CVE-2024-25422Proof of concept | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCsem-cms · semcms · CWE-89 | Critical9.8 | — | 1.0% | Feb 28, 2024 |
39Monitor | CVE-2020-18078No exploit | A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.sem-cms · semcms | Critical9.8 | — | 1.0% | Dec 17, 2021 |
39Monitor | CVE-2020-18432No exploit | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.sem-cms · semcms · CWE-434 | Critical9.8 | — | 0.9% | Jun 29, 2023 |
39Monitor | CVE-2021-38729No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38730No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38734No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38737No exploit | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38736No exploit | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38732No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2021-38217No exploit | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Oct 28, 2022 |
39Monitor | CVE-2023-30090No exploit | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php.sem-cms · semcms · CWE-434 | Critical9.8 | — | 0.8% | May 4, 2023 |
39Monitor | CVE-2024-30938No exploit | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_Usersem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | Apr 18, 2024 |
39Monitor | CVE-2023-31707No exploit | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.8% | May 19, 2023 |
39Monitor | CVE-2022-2726No exploit | SEMCMS Ant_Check.php sql injectionsem-cms · semcms · CWE-89 | Critical9.8 | — | 0.7% | Aug 9, 2022 |
39Monitor | CVE-2021-38733No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.7% | Oct 28, 2022 |
39Monitor | CVE-2021-38731No exploit | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.7% | Oct 28, 2022 |
39Monitor | CVE-2023-50563No exploit | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.6% | Dec 14, 2023 |
39Monitor | CVE-2023-37647No exploit | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.6% | Jul 31, 2023 |
39Monitor | CVE-2024-46103No exploit | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.sem-cms · semcms · CWE-94 | Critical9.8 | — | 0.5% | Sep 20, 2024 |
39Monitor | CVE-2025-25686No exploit | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.sem-cms · semcms · CWE-89 | Critical9.8 | — | 0.5% | Mar 27, 2025 |
35Monitor | CVE-2018-18742No exploit | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.sem-cms · semcms · CWE-352 | High8.8 | — | 0.5% | Oct 29, 2018 |
30Monitor | CVE-2020-18081No exploit | The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext thsem-cms · semcms · CWE-89 | High7.5 | — | 1.1% | Dec 17, 2021 |
30Monitor | CVE-2023-48863No exploit | SEMCMS 3.9 is vulnerable to SQL Injection.sem-cms · semcms · CWE-89 | High7.5 | — | 0.9% | Dec 4, 2023 |
30Monitor | CVE-2024-31010No exploit | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.sem-cms · semcms · CWE-89 | High7.5 | — | 0.8% | Apr 3, 2024 |
- CVE-2024-3101239Monitor
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive inform
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsApr 3, 2024
- CVE-2024-2542239Monitor
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMC
CriticalCVSS 9.8Proof of conceptEPSS 1%sem-cms · semcmsFeb 28, 2024
- CVE-2020-1807839Monitor
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsDec 17, 2021
- CVE-2020-1843239Monitor
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsJun 29, 2023
- CVE-2021-3872939Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873039Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873439Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873739Monitor
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873639Monitor
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873239Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3821739Monitor
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2023-3009039Monitor
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsMay 4, 2023
- CVE-2024-3093839Monitor
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsApr 18, 2024
- CVE-2023-3170739Monitor
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsMay 19, 2023
- CVE-2022-272639Monitor
SEMCMS Ant_Check.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsAug 9, 2022
- CVE-2021-3873339Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2021-3873139Monitor
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsOct 28, 2022
- CVE-2023-5056339Monitor
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsDec 14, 2023
- CVE-2023-3764739Monitor
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsJul 31, 2023
- CVE-2024-4610339Monitor
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsSep 20, 2024
- CVE-2025-2568639Monitor
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
CriticalCVSS 9.8No exploitEPSS 1%sem-cms · semcmsMar 27, 2025
- CVE-2018-1874235Monitor
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
HighCVSS 8.8No exploitEPSS 1%sem-cms · semcmsOct 29, 2018
- CVE-2020-1808130Monitor
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext th
HighCVSS 7.5No exploitEPSS 1%sem-cms · semcmsDec 17, 2021
- CVE-2023-4886330Monitor
SEMCMS 3.9 is vulnerable to SQL Injection.
HighCVSS 7.5No exploitEPSS 1%sem-cms · semcmsDec 4, 2023
- CVE-2024-3101030Monitor
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
HighCVSS 7.5No exploitEPSS 1%sem-cms · semcmsApr 3, 2024