CVE-2026-79423
- EPSS 0.24%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:04:24
An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2026-85138
- EPSS 0.39%
- Veröffentlicht 03.09.2026 15:45:07
- Zuletzt bearbeitet 03.09.2026 17:25:25
A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely...
CVE-2026-85137
- EPSS 0.49%
- Veröffentlicht 03.09.2026 15:15:08
- Zuletzt bearbeitet 05.09.2026 02:17:18
A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be ini...
CVE-2026-82603
- EPSS 0.3%
- Veröffentlicht 31.08.2026 01:45:07
- Zuletzt bearbeitet 01.09.2026 15:17:33
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may b...
CVE-2026-82602
- EPSS 0.31%
- Veröffentlicht 31.08.2026 01:30:09
- Zuletzt bearbeitet 31.08.2026 20:56:08
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed public...
- EPSS 0.28%
- Veröffentlicht 31.08.2026 01:15:07
- Zuletzt bearbeitet 31.08.2026 20:56:08
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made a...
CVE-2026-82600
- EPSS 0.25%
- Veröffentlicht 31.08.2026 01:00:13
- Zuletzt bearbeitet 31.08.2026 22:17:26
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated re...
CVE-2026-82599
- EPSS 0.31%
- Veröffentlicht 31.08.2026 00:45:08
- Zuletzt bearbeitet 31.08.2026 20:56:08
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. I...
CVE-2026-82598
- EPSS 0.31%
- Veröffentlicht 31.08.2026 00:30:07
- Zuletzt bearbeitet 01.09.2026 15:17:33
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack r...
CVE-2020-36932
- EPSS 0.24%
- Veröffentlicht 25.01.2026 13:04:16
- Zuletzt bearbeitet 02.02.2026 16:16:14
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.