Seacms kayıtları
seacms üreticisine ait 114 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')25
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-94 Improper Control of Generation of Code ('Code Injection')18
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
114 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2022-27336İstismar yok | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.seacms · seacms | Kritik9,8 | — | %20,5 | 27 Nis 2022 |
40Planlayın | CVE-2024-29275Kavram kanıtı | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive iseacms · seacms · CWE-89 | Kritik9,8 | — | %5,0 | 22 Mar 2024 |
40Planlayın | CVE-2021-37358İstismar yok | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checseacms · seacms · CWE-89 | Kritik9,8 | — | %2,3 | 18 Ağu 2021 |
40Planlayın | CVE-2022-23878İstismar yok | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.seacms · seacms | Kritik9,8 | — | %2,2 | 2 Mar 2022 |
40Planlayın | CVE-2020-21378Kavram kanıtı | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.seacms · seacms · CWE-89 | Kritik9,8 | — | %2,1 | 21 Ara 2020 |
39İzleyin | CVE-2023-44169İstismar yok | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.seacms · seacms · CWE-22 | Kritik9,8 | — | %1,4 | 27 Eyl 2023 |
39İzleyin | CVE-2023-43216İstismar yok | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.seacms · seacms · CWE-22 | Kritik9,8 | — | %1,4 | 27 Eyl 2023 |
39İzleyin | CVE-2023-44172İstismar yok | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.seacms · seacms · CWE-22 | Kritik9,8 | — | %1,4 | 27 Eyl 2023 |
39İzleyin | CVE-2023-44171İstismar yok | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.seacms · seacms · CWE-22 | Kritik9,8 | — | %1,4 | 27 Eyl 2023 |
39İzleyin | CVE-2023-44170İstismar yok | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.seacms · seacms · CWE-22 | Kritik9,8 | — | %1,4 | 27 Eyl 2023 |
39İzleyin | CVE-2018-16822İstismar yok | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.seacms · seacms · CWE-89 | Kritik9,8 | — | %1,2 | 21 Eyl 2018 |
39İzleyin | CVE-2023-46010İstismar yok | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.seacms · seacms · CWE-94 | Kritik9,8 | — | %1,2 | 25 Eki 2023 |
39İzleyin | CVE-2024-55461İstismar yok | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().seacms · seacms · CWE-77 | Kritik9,8 | — | %1,1 | 18 Ara 2024 |
39İzleyin | CVE-2018-16445İstismar yok | An issue was discovered in SeaCMS through 6.61.seacms · seacms · CWE-89 | Kritik9,8 | — | %1,1 | 4 Eyl 2018 |
39İzleyin | CVE-2024-39028İstismar yok | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.seacms · seacms · CWE-77 | Kritik9,8 | — | %1,1 | 5 Tem 2024 |
39İzleyin | CVE-2024-46640İstismar yok | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.seacms · seacms · CWE-94 | Kritik9,8 | — | %1,0 | 20 Eyl 2024 |
39İzleyin | CVE-2023-0960İstismar yok | SeaCMS Picture Management config.ftp.php deserializationseacms · seacms · CWE-502 | Kritik9,8 | — | %1,0 | 22 Şub 2023 |
39İzleyin | CVE-2023-43222İstismar yok | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.seacms · seacms · CWE-94 | Kritik9,8 | — | %1,0 | 27 Eyl 2023 |
39İzleyin | CVE-2025-44071İstismar yok | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.seacms · seacms · CWE-94 | Kritik9,8 | — | %1,0 | 5 May 2025 |
39İzleyin | CVE-2022-43256İstismar yok | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.seacms · seacms · CWE-89 | Kritik9,8 | — | %0,9 | 16 Kas 2022 |
39İzleyin | CVE-2021-39426İstismar yok | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 paraseacms · seacms · CWE-94 | Kritik9,8 | — | %0,9 | 15 Ara 2022 |
39İzleyin | CVE-2025-22974İstismar yok | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter iseacms · seacms · CWE-89 | Kritik9,8 | — | %0,8 | 24 Şub 2025 |
39İzleyin | CVE-2024-44921İstismar yok | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.seacms · seacms · CWE-89 | Kritik9,8 | — | %0,6 | 3 Eyl 2024 |
39İzleyin | CVE-2024-44721İstismar yok | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.seacms · seacms · CWE-918 | Kritik9,8 | — | %0,6 | 9 Eyl 2024 |
39İzleyin | CVE-2025-25513İstismar yok | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.seacms · seacms · CWE-89 | Kritik9,8 | — | %0,5 | 24 Şub 2025 |
- CVE-2022-2733645Planlayın
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
KritikCVSS 9,8İstismar yokEPSS %21seacms · seacms27 Nis 2022
- CVE-2024-2927540Planlayın
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive i
KritikCVSS 9,8Kavram kanıtıEPSS %5seacms · seacms22 Mar 2024
- CVE-2021-3735840Planlayın
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=chec
KritikCVSS 9,8İstismar yokEPSS %2seacms · seacms18 Ağu 2021
- CVE-2022-2387840Planlayın
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
KritikCVSS 9,8İstismar yokEPSS %2seacms · seacms2 Mar 2022
- CVE-2020-2137840Planlayın
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
KritikCVSS 9,8Kavram kanıtıEPSS %2seacms · seacms21 Ara 2020
- CVE-2023-4416939İzleyin
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2023-4321639İzleyin
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2023-4417239İzleyin
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2023-4417139İzleyin
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2023-4417039İzleyin
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2018-1682239İzleyin
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms21 Eyl 2018
- CVE-2023-4601039İzleyin
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms25 Eki 2023
- CVE-2024-5546139İzleyin
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms18 Ara 2024
- CVE-2018-1644539İzleyin
An issue was discovered in SeaCMS through 6.61.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms4 Eyl 2018
- CVE-2024-3902839İzleyin
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms5 Tem 2024
- CVE-2024-4664039İzleyin
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms20 Eyl 2024
- CVE-2023-096039İzleyin
SeaCMS Picture Management config.ftp.php deserialization
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms22 Şub 2023
- CVE-2023-4322239İzleyin
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms27 Eyl 2023
- CVE-2025-4407139İzleyin
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms5 May 2025
- CVE-2022-4325639İzleyin
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms16 Kas 2022
- CVE-2021-3942639İzleyin
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 para
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms15 Ara 2022
- CVE-2025-2297439İzleyin
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter i
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms24 Şub 2025
- CVE-2024-4492139İzleyin
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms3 Eyl 2024
- CVE-2024-4472139İzleyin
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms9 Eyl 2024
- CVE-2025-2551339İzleyin
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
KritikCVSS 9,8İstismar yokEPSS %1seacms · seacms24 Şub 2025