sem-cms kayıtları
sem-cms üreticisine ait 59 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')36
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
59 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-31012İstismar yok | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive informsem-cms · semcms · CWE-434 | Kritik9,8 | — | %1,2 | 3 Nis 2024 |
39İzleyin | CVE-2024-25422Kavram kanıtı | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCsem-cms · semcms · CWE-89 | Kritik9,8 | — | %1,0 | 28 Şub 2024 |
39İzleyin | CVE-2020-18078İstismar yok | A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.sem-cms · semcms | Kritik9,8 | — | %1,0 | 17 Ara 2021 |
39İzleyin | CVE-2020-18432İstismar yok | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.sem-cms · semcms · CWE-434 | Kritik9,8 | — | %0,9 | 29 Haz 2023 |
39İzleyin | CVE-2021-38729İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38730İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38734İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38737İstismar yok | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38736İstismar yok | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38732İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2021-38217İstismar yok | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 28 Eki 2022 |
39İzleyin | CVE-2023-30090İstismar yok | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php.sem-cms · semcms · CWE-434 | Kritik9,8 | — | %0,8 | 4 May 2023 |
39İzleyin | CVE-2024-30938İstismar yok | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_Usersem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 18 Nis 2024 |
39İzleyin | CVE-2023-31707İstismar yok | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,8 | 19 May 2023 |
39İzleyin | CVE-2022-2726İstismar yok | SEMCMS Ant_Check.php sql injectionsem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,7 | 9 Ağu 2022 |
39İzleyin | CVE-2021-38733İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,7 | 28 Eki 2022 |
39İzleyin | CVE-2021-38731İstismar yok | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,7 | 28 Eki 2022 |
39İzleyin | CVE-2023-50563İstismar yok | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,6 | 14 Ara 2023 |
39İzleyin | CVE-2023-37647İstismar yok | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,6 | 31 Tem 2023 |
39İzleyin | CVE-2024-46103İstismar yok | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.sem-cms · semcms · CWE-94 | Kritik9,8 | — | %0,5 | 20 Eyl 2024 |
39İzleyin | CVE-2025-25686İstismar yok | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.sem-cms · semcms · CWE-89 | Kritik9,8 | — | %0,5 | 27 Mar 2025 |
35İzleyin | CVE-2018-18742İstismar yok | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.sem-cms · semcms · CWE-352 | Yüksek8,8 | — | %0,5 | 29 Eki 2018 |
30İzleyin | CVE-2020-18081İstismar yok | The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext thsem-cms · semcms · CWE-89 | Yüksek7,5 | — | %1,1 | 17 Ara 2021 |
30İzleyin | CVE-2023-48863İstismar yok | SEMCMS 3.9 is vulnerable to SQL Injection.sem-cms · semcms · CWE-89 | Yüksek7,5 | — | %0,9 | 4 Ara 2023 |
30İzleyin | CVE-2024-31010İstismar yok | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.sem-cms · semcms · CWE-89 | Yüksek7,5 | — | %0,8 | 3 Nis 2024 |
- CVE-2024-3101239İzleyin
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive inform
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms3 Nis 2024
- CVE-2024-2542239İzleyin
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMC
KritikCVSS 9,8Kavram kanıtıEPSS %1sem-cms · semcms28 Şub 2024
- CVE-2020-1807839İzleyin
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms17 Ara 2021
- CVE-2020-1843239İzleyin
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms29 Haz 2023
- CVE-2021-3872939İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873039İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873439İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873739İzleyin
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873639İzleyin
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873239İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3821739İzleyin
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2023-3009039İzleyin
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms4 May 2023
- CVE-2024-3093839İzleyin
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms18 Nis 2024
- CVE-2023-3170739İzleyin
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms19 May 2023
- CVE-2022-272639İzleyin
SEMCMS Ant_Check.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms9 Ağu 2022
- CVE-2021-3873339İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2021-3873139İzleyin
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms28 Eki 2022
- CVE-2023-5056339İzleyin
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms14 Ara 2023
- CVE-2023-3764739İzleyin
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms31 Tem 2023
- CVE-2024-4610339İzleyin
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms20 Eyl 2024
- CVE-2025-2568639İzleyin
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
KritikCVSS 9,8İstismar yokEPSS %1sem-cms · semcms27 Mar 2025
- CVE-2018-1874235İzleyin
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
YüksekCVSS 8,8İstismar yokEPSS %1sem-cms · semcms29 Eki 2018
- CVE-2020-1808130İzleyin
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext th
YüksekCVSS 7,5İstismar yokEPSS %1sem-cms · semcms17 Ara 2021
- CVE-2023-4886330İzleyin
SEMCMS 3.9 is vulnerable to SQL Injection.
YüksekCVSS 7,5İstismar yokEPSS %1sem-cms · semcms4 Ara 2023
- CVE-2024-3101030İzleyin
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
YüksekCVSS 7,5İstismar yokEPSS %1sem-cms · semcms3 Nis 2024