Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Seeddms HIGH 7.2
CVE-2025-45752

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality i…

No fix yet
Fix from $1,950 2025-05-21
Seeddms MEDIUM 5.4
CVE-2025-45754

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payl…

No fix yet
Fix from $1,600 2025-05-21
Seeddms MEDIUM 5.4
CVE-2025-25461

A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a mal…

No fix yet
Fix from $1,600 2025-02-28
Seeddms MEDIUM 5.4
CVE-2024-46409

A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafte…

No fix yet
Fix from $1,600 2024-10-04
Seeddms MEDIUM 6.1
CVE-2021-39421

A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Mitigation only
Fix from $1,600 2023-07-24
Seeddms MEDIUM 6.1
CVE-2021-39425

SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary w…

Mitigation only
Fix from $1,600 2023-07-20
Seeddms HIGH 8.8
CVE-2021-33223

An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.

No fix yet
Fix from $1,950 2023-06-07
Seeddms CRITICAL 9.8
CVE-2022-44938

Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

No fix yet
Fix from $2,300 2022-12-08
Seeddms MEDIUM 6.5
CVE-2022-28478

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sani…

Patch available
Fix from $1,600 2022-06-06
Seeddms MEDIUM 5.4
CVE-2022-28051

The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an att…

Patch available
Fix from $1,600 2022-06-06
Seeddms MEDIUM 6.1
CVE-2021-45408

Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using …

No fix yet
Fix from $1,600 2022-02-04
Seeddms MEDIUM 6.1
CVE-2020-23048

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name an…

No fix yet
Fix from $1,600 2021-10-22
Seeddms MEDIUM 6.1
CVE-2020-28727

Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

Patch available
Fix from $1,600 2020-12-07
Seeddms MEDIUM 6.1
CVE-2020-28726

Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

Patch available
Fix from $1,600 2020-11-24
Seeddms MEDIUM 6.1
CVE-2019-12932

A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header …

Mitigation only
Fix from $1,600 2019-06-28
Seeddms HIGH 7.5
CVE-2019-12744EPSS 12%

SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-201…

Fix: 5.1.11+
Fix from $1,950 2019-06-20
Seeddms MEDIUM 5.4
CVE-2019-12745

out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.

Fix: 5.1.11+
Fix from $1,600 2019-06-20
Seeddms MEDIUM 6.1
CVE-2019-12801

out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.

No fix yet
Fix from $1,600 2019-06-17
Seeddms HIGH 8.8
CVE-2018-12940

Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to ex…

Fix: 5.1.8+
Fix from $1,950 2018-07-31
Seeddms HIGH 8.8
CVE-2018-12941

This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command …

Fix: 5.1.8+
Fix from $1,950 2018-07-31
Seeddms HIGH 8.8
CVE-2018-12942

SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attacke…

Fix: 5.1.8+
Fix from $1,950 2018-07-31
Seeddms MEDIUM 6.5
CVE-2018-12939

A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) …

Fix: 5.1.8+
Fix from $1,600 2018-07-31
Seeddms MEDIUM 6.1
CVE-2018-12943

Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 …

Fix: 5.1.8+
Fix from $1,600 2018-07-31
Seeddms MEDIUM 6.1
CVE-2018-12944

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote at…

Fix: 5.1.8+
Fix from $1,600 2018-07-31
Seeddms MEDIUM 6.4
CVE-2014-2279EPSS 5%

Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with access to…

Fix: after 4.3.3
Fix from $1,600 2014-10-17
Seeddms MEDIUM 5.1
CVE-2014-2278

Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute …

Fix: after 4.3.3
Fix from $1,600 2014-10-17