CVE-2025-4257
- EPSS 0.16%
- Veröffentlicht 05.05.2025 01:00:07
- Zuletzt bearbeitet 06.10.2025 16:28:34
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack may be init...
CVE-2025-4256
- EPSS 0.16%
- Veröffentlicht 05.05.2025 00:31:03
- Zuletzt bearbeitet 12.06.2025 19:22:02
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. T...
CVE-2025-44071
- EPSS 3.9%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 13.05.2025 20:03:39
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
CVE-2025-44072
- EPSS 0.27%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 13.05.2025 20:05:16
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
CVE-2025-44074
- EPSS 0.27%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 13.05.2025 20:05:29
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
CVE-2025-3797
- EPSS 0.2%
- Veröffentlicht 19.04.2025 07:00:12
- Zuletzt bearbeitet 15.07.2025 20:05:53
A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack can be initiated remot...
CVE-2025-3792
- EPSS 0.2%
- Veröffentlicht 18.04.2025 15:00:05
- Zuletzt bearbeitet 15.07.2025 20:06:10
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may...
CVE-2025-29647
- EPSS 0.27%
- Veröffentlicht 03.04.2025 19:15:39
- Zuletzt bearbeitet 08.04.2025 20:15:30
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVE-2025-25802
- EPSS 0.09%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 28.03.2025 16:59:38
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
CVE-2025-25813
- EPSS 0.09%
- Veröffentlicht 26.02.2025 15:15:28
- Zuletzt bearbeitet 28.03.2025 16:59:27
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.