Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-45752 A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality i… Seeddms No fix yet Fix from $1,9502025-05-21 MEDIUM 5.4 CVE-2025-45754 A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payl… Seeddms No fix yet Fix from $1,6002025-05-21 MEDIUM 5.4 CVE-2025-25461 A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a mal… Seeddms No fix yet Fix from $1,6002025-02-28 MEDIUM 5.4 CVE-2024-46409 A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafte… Seeddms No fix yet Fix from $1,6002024-10-04 MEDIUM 6.1 CVE-2021-39421 A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Seeddms Mitigation only Fix from $1,6002023-07-24 MEDIUM 6.1 CVE-2021-39425 SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary w… Seeddms Mitigation only Fix from $1,6002023-07-20 HIGH 8.8 CVE-2021-33223 An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file. Seeddms No fix yet Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2022-44938 Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack. Seeddms No fix yet Fix from $2,3002022-12-08 MEDIUM 6.1 CVE-2021-45408 Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using … Seeddms No fix yet Fix from $1,6002022-02-04 MEDIUM 6.1 CVE-2020-23048 SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name an… Seeddms No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2019-12932 A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header … Seeddms Mitigation only Fix from $1,6002019-06-28 MEDIUM 6.1 CVE-2019-12801 out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. Seeddms No fix yet Fix from $1,6002019-06-17