CVE-2020-36932
- EPSS 0.01%
- Veröffentlicht 25.01.2026 13:04:16
- Zuletzt bearbeitet 02.02.2026 16:16:14
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
CVE-2025-15003
- EPSS 0.04%
- Veröffentlicht 21.12.2025 23:32:07
- Zuletzt bearbeitet 24.02.2026 06:16:33
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performing a manipulation of the argument e_id results in sql injection. The attack is possible to be carried out remotely. The e...
CVE-2025-15002
- EPSS 0.04%
- Veröffentlicht 21.12.2025 23:02:07
- Zuletzt bearbeitet 30.12.2025 22:20:25
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be execut...
CVE-2025-60449
- EPSS 0.05%
- Veröffentlicht 03.10.2025 00:00:00
- Zuletzt bearbeitet 08.10.2025 15:20:55
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not on...
CVE-2025-11071
- EPSS 0.02%
- Veröffentlicht 27.09.2025 18:15:36
- Zuletzt bearbeitet 10.10.2025 18:37:42
A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of the component Cron Task Management Module. The manipulation of the argument resourcefrom/collectID leads to sql injecti...
CVE-2025-10662
- EPSS 0.03%
- Veröffentlicht 18.09.2025 10:32:05
- Zuletzt bearbeitet 19.09.2025 20:30:03
A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_members.php?ac=editsave. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit...
CVE-2025-50592
- EPSS 0.04%
- Veröffentlicht 05.08.2025 00:00:00
- Zuletzt bearbeitet 15.08.2025 16:06:43
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
CVE-2025-6864
- EPSS 0.04%
- Veröffentlicht 29.06.2025 16:00:09
- Zuletzt bearbeitet 01.07.2025 12:27:47
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launc...
CVE-2024-40570
- EPSS 0.09%
- Veröffentlicht 17.06.2025 00:00:00
- Zuletzt bearbeitet 23.06.2025 13:59:30
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.
CVE-2025-44073
- EPSS 0.27%
- Veröffentlicht 06.05.2025 21:16:19
- Zuletzt bearbeitet 12.06.2025 17:09:21
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.