Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Seacms MEDIUM 6.5
CVE-2025-25514

Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

Fix: after 13.3
Fix from $1,600 2025-02-25
Seacms CRITICAL 9.8
CVE-2025-22974

SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the pho…

Fix: after 13.2
Fix from $2,300 2025-02-24
Seacms CRITICAL 9.8
CVE-2025-25513

Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

Fix: after 13.3
Fix from $2,300 2025-02-24
Seacms CRITICAL 9.1
CVE-2024-54880

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

No fix yet
Fix from $2,300 2025-01-06
Seacms CRITICAL 9.1
CVE-2024-54879

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinite…

No fix yet
Fix from $2,300 2025-01-06
Seacms CRITICAL 9.8
CVE-2024-55461

SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

Fix: after 13.0
Fix from $2,300 2024-12-18
Seacms HIGH 8.8
CVE-2024-50808

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to u…

No fix yet
Fix from $1,950 2024-11-08
Seacms CRITICAL 9.8
CVE-2024-46640

SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function…

No fix yet
Fix from $2,300 2024-09-20
Seacms CRITICAL 9.8
CVE-2024-44721

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

No fix yet
Fix from $2,300 2024-09-09
Seacms HIGH 7.5
CVE-2024-44720

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

No fix yet
Fix from $1,950 2024-09-09
Seacms CRITICAL 9.8
CVE-2024-44921

SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

No fix yet
Fix from $2,300 2024-09-03
Seacms MEDIUM 6.1
CVE-2024-44920

A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts …

No fix yet
Fix from $1,600 2024-09-03
Seacms MEDIUM 6.1
CVE-2024-44683

Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

Mitigation only
Fix from $1,600 2024-08-30
Seacms HIGH 7.2
CVE-2024-44916

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php f…

No fix yet
Fix from $1,950 2024-08-30
Seacms MEDIUM 5.4
CVE-2024-44919

A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML v…

No fix yet
Fix from $1,600 2024-08-29
Seacms CRITICAL 9.8
CVE-2024-41444

SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.

Mitigation only
Fix from $2,300 2024-08-26
Seacms HIGH 8.8
CVE-2024-42599

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edi…

No fix yet
Fix from $1,950 2024-08-22
Seacms MEDIUM 6.7
CVE-2024-42598

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions o…

No fix yet
Fix from $1,600 2024-08-20
Seacms MEDIUM 6.1
CVE-2024-7163

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/i…

No fix yet
Fix from $1,600 2024-07-28
Seacms MEDIUM 6.5
CVE-2024-7161

A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.ph…

No fix yet
Fix from $1,600 2024-07-28
Seacms MEDIUM 5.4
CVE-2024-7162

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the…

No fix yet
Fix from $1,600 2024-07-28
Seacms MEDIUM 6.5
CVE-2024-39036

SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

No fix yet
Fix from $1,600 2024-07-16
Seacms HIGH 8.8
CVE-2024-40521

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrict…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40522

There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in with…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40518

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input d…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40519

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input dat…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40520

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user in…

No fix yet
Fix from $1,950 2024-07-12
Seacms CRITICAL 9.8
CVE-2024-39028

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

Fix: after 12.9
Fix from $2,300 2024-07-05
Seacms HIGH 7.5
CVE-2024-39027

SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/playe…

No fix yet
Fix from $1,950 2024-07-05
Seacms CRITICAL 9.8
CVE-2024-6416

A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /j…

No fix yet
Fix from $2,300 2024-06-30