Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-25514
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-22974
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the pho…
Seacms
after 13.2
CRITICAL 9.8
CVE-2025-25513
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
Seacms
after 13.3
CRITICAL 9.1
CVE-2024-54880
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Seacms
No fix yet
CRITICAL 9.1
CVE-2024-54879
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinite…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-55461
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
Seacms
after 13.0
HIGH 8.8
CVE-2024-50808
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to u…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-46640
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-44721
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
Seacms
No fix yet
HIGH 7.5
CVE-2024-44720
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-44921
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
Seacms
No fix yet
MEDIUM 6.1
CVE-2024-44920
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts …
Seacms
No fix yet
MEDIUM 6.1
CVE-2024-44683
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
Seacms
Mitigation only
HIGH 7.2
CVE-2024-44916
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php f…
Seacms
No fix yet
MEDIUM 5.4
CVE-2024-44919
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML v…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-41444
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
Seacms
Mitigation only
HIGH 8.8
CVE-2024-42599
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edi…
Seacms
No fix yet
MEDIUM 6.7
CVE-2024-42598
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions o…
Seacms
No fix yet
MEDIUM 6.1
CVE-2024-7163
A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/i…
Seacms
No fix yet
MEDIUM 6.5
CVE-2024-7161
A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.ph…
Seacms
No fix yet
MEDIUM 5.4
CVE-2024-7162
A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the…
Seacms
No fix yet
MEDIUM 6.5
CVE-2024-39036
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
Seacms
No fix yet
HIGH 8.8
CVE-2024-40521
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrict…
Seacms
No fix yet
HIGH 8.8
CVE-2024-40522
There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in with…
Seacms
No fix yet
HIGH 8.8
CVE-2024-40518
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input d…
Seacms
No fix yet
HIGH 8.8
CVE-2024-40519
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input dat…
Seacms
No fix yet
HIGH 8.8
CVE-2024-40520
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user in…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-39028
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
Seacms
after 12.9
HIGH 7.5
CVE-2024-39027
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/playe…
Seacms
No fix yet
CRITICAL 9.8
CVE-2024-6416
A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /j…
Seacms
No fix yet