Skip to content
Noroxi

sem-cms records

59 published records for vendor sem-cms.

All records

59 records
  • An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive inform

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsApr 3, 2024

  • SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMC

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    sem-cms · semcmsFeb 28, 2024

  • A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsDec 17, 2021

  • File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsJun 29, 2023

  • SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsMay 4, 2023

  • SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsApr 18, 2024

  • SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsMay 19, 2023

  • CVE-2022-2726
    39Monitor

    SEMCMS Ant_Check.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsAug 9, 2022

  • SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsOct 28, 2022

  • Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsDec 14, 2023

  • SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsJul 31, 2023

  • SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsSep 20, 2024

  • semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    sem-cms · semcmsMar 27, 2025

  • A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.

    HighCVSS 8.8No exploitEPSS 1%

    sem-cms · semcmsOct 29, 2018

  • The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext th

    HighCVSS 7.5No exploitEPSS 1%

    sem-cms · semcmsDec 17, 2021

  • SEMCMS 3.9 is vulnerable to SQL Injection.

    HighCVSS 7.5No exploitEPSS 1%

    sem-cms · semcmsDec 4, 2023

  • SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.

    HighCVSS 7.5No exploitEPSS 1%

    sem-cms · semcmsApr 3, 2024