Home/Product/seacms
Product

seacms

116 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-36932
all versions
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers
6.1MEDIUM
CVE-2025-15003
>= 13.0 and <= 13.3
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performin
4.7MEDIUM
CVE-2025-15002
>= 13.0 and <= 13.3
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dm
7.3HIGH
CVE-2025-60449
all versions
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php compone
4.9MEDIUM
CVE-2025-11071
all versions
A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of
4.7MEDIUM
CVE-2025-10662
<= 13.3
A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_members.php?ac
4.7MEDIUM
CVE-2025-50592
< 13.2
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
5.4MEDIUM
CVE-2025-6864
<= 13.2
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown
4.3MEDIUM
CVE-2024-40570
all versions
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php
6.5MEDIUM
CVE-2025-44073
all versions
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
9.8CRITICAL
CVE-2025-44074
all versions
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
9.8CRITICAL
CVE-2025-44072
all versions
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
9.8CRITICAL
CVE-2025-44071
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerabil
9.8CRITICAL
CVE-2025-4257
all versions
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of
3.5LOW
CVE-2025-4256
all versions
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_pay
3.5LOW
CVE-2025-3797
<= 13.3
A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_
4.7MEDIUM
CVE-2025-3792
<= 13.3
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing
4.7MEDIUM
CVE-2025-29647
all versions
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
9.8CRITICAL
CVE-2025-25813
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
5.1MEDIUM
CVE-2025-25802
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
5.1MEDIUM
CVE-2025-25800
all versions
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.ph
5.3MEDIUM
CVE-2025-25799
all versions
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
6.0MEDIUM
CVE-2025-25797
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
5.1MEDIUM
CVE-2025-25796
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
5.1MEDIUM
CVE-2025-25794
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
5.1MEDIUM
CVE-2025-25793
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
5.1MEDIUM
CVE-2025-25792
all versions
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.
4.4MEDIUM
CVE-2025-25521
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
9.8CRITICAL
CVE-2025-25520
<= 13.3
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
9.8CRITICAL
CVE-2025-25519
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
9.8CRITICAL
CVE-2025-25517
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
9.8CRITICAL
CVE-2025-25516
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
9.8CRITICAL
CVE-2025-25515
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
8.8HIGH
CVE-2025-25514
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
6.5MEDIUM
CVE-2025-22974
<= 13.2
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql p
9.8CRITICAL
CVE-2025-25513
<= 13.3
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
9.8CRITICAL
CVE-2024-54880
all versions
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register
9.1CRITICAL
CVE-2024-54879
all versions
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge
9.1CRITICAL
CVE-2024-55461
<= 13.0
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
9.8CRITICAL
CVE-2024-50808
all versions
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend us
8.8HIGH
CVE-2024-46640
all versions
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function,
9.8CRITICAL
CVE-2024-44721
all versions
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
9.8CRITICAL
CVE-2024-44720
all versions
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
7.5HIGH
CVE-2024-44921
all versions
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
9.8CRITICAL
CVE-2024-44920
all versions
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arb
6.1MEDIUM
CVE-2024-44683
all versions
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
6.1MEDIUM
CVE-2024-44918
all versions
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbit
3.5LOW
CVE-2024-44916
all versions
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the
7.2HIGH
CVE-2024-44919
all versions
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary we
5.4MEDIUM
CVE-2024-41444
all versions
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
9.8CRITICAL
CVE-2024-42599
all versions
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes
8.8HIGH
CVE-2024-42598
all versions
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imp
6.7MEDIUM
CVE-2024-7163
all versions
A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/playe
3.5LOW
CVE-2024-7162
all versions
A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown f
3.5LOW
CVE-2024-7161
all versions
A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of
4.3MEDIUM
CVE-2024-39036
all versions
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
6.5MEDIUM
CVE-2024-40522
all versions
There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable n
8.8HIGH
CVE-2024-40521
all versions
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php impos
8.8HIGH
CVE-2024-40520
all versions
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and
8.8HIGH
CVE-2024-40519
all versions
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing
8.8HIGH
CVE-2024-40518
all versions
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writi
8.8HIGH
CVE-2024-39028
<= 12.9
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
9.8CRITICAL
CVE-2024-39027
all versions
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid par
7.5HIGH
CVE-2024-6416
all versions
A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functiona
6.3MEDIUM
CVE-2024-31611
all versions
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
9.1CRITICAL
CVE-2024-30565
all versions
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
8.8HIGH
CVE-2024-29275
all versions
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain s
9.8CRITICAL
CVE-2023-50470
all versions
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary
5.4MEDIUM
CVE-2023-46987
all versions
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
8.8HIGH
CVE-2023-46010
<= 12.9
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
9.8CRITICAL
CVE-2023-44848
<= 12.8
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.
8.1HIGH
CVE-2023-44847
<= 12.8
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
7.2HIGH
CVE-2023-44846
<= 12.8
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
8.8HIGH
CVE-2023-44172
all versions
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
9.8CRITICAL
CVE-2023-44171
all versions
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
9.8CRITICAL
CVE-2023-44170
all versions
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
9.8CRITICAL
CVE-2023-44169
all versions
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
9.8CRITICAL
CVE-2023-43222
< 12.8
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
9.8CRITICAL
CVE-2023-43216
all versions
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
9.8CRITICAL
CVE-2023-43278
<= 12.8
A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin accoun
8.8HIGH
CVE-2023-37125
all versions
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execut
5.4MEDIUM
CVE-2023-37124
all versions
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary w
5.4MEDIUM
CVE-2023-2926
all versions
A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file mem
5.4MEDIUM
CVE-2023-0960
all versions
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of th
4.7MEDIUM
CVE-2022-48093
all versions
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
7.2HIGH
CVE-2021-39426
all versions
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the no
9.8CRITICAL
CVE-2022-43256
< 12.6
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
9.8CRITICAL
CVE-2022-28076
all versions
Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
7.2HIGH
CVE-2022-27336
all versions
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
9.8CRITICAL
CVE-2022-23878
all versions
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
9.8CRITICAL
CVE-2021-37358
all versions
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?a
9.8CRITICAL
CVE-2021-29313
all versions
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
6.1MEDIUM
CVE-2020-28846
all versions
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add a
6.5MEDIUM
CVE-2020-26642
all versions
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to
6.1MEDIUM
CVE-2020-21378
all versions
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
9.8CRITICAL
CVE-2019-8418
all versions
SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.
8.8HIGH
CVE-2018-19350
all versions
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstr
5.4MEDIUM
CVE-2018-19349
all versions
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.p
7.2HIGH
CVE-2018-17365
all versions
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
7.5HIGH
CVE-2018-17321
all versions
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset actio
6.1MEDIUM
CVE-2018-16822
all versions
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
9.8CRITICAL
CVE-2018-16821
all versions
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
5.3MEDIUM
CVE-2018-17062
all versions
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recy
6.1MEDIUM
CVE-2018-16446
<= 6.61
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via dir
7.5HIGH
CVE-2018-16445
<= 6.61
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request
9.8CRITICAL
CVE-2018-16444
all versions
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
9.1CRITICAL
CVE-2018-16348
all versions
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
4.8MEDIUM
CVE-2018-16343
all versions
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $G
7.2HIGH
CVE-2018-14910
all versions
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n
8.8HIGH
CVE-2018-14517
all versions
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
6.1MEDIUM
CVE-2018-14421
all versions
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v&#95;pic) to /admin/admin_video.php
8.8HIGH
CVE-2018-13445
all versions
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?acti
8.8HIGH
CVE-2018-13444
all versions
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?ac
8.8HIGH
CVE-2018-12431
all versions
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
4.8MEDIUM
CVE-2018-11583
all versions
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
6.1MEDIUM
CVE-2017-17561
all versions
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping
7.2HIGH
threatengine.sh