Home/Product/sem cms semcms
Product

sem cms semcms

59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1552
all versions
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. Th
6.3MEDIUM
CVE-2025-51660
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
5.4MEDIUM
CVE-2025-51659
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
5.4MEDIUM
CVE-2025-51658
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
5.4MEDIUM
CVE-2025-51657
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
5.4MEDIUM
CVE-2025-51656
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
5.4MEDIUM
CVE-2025-51655
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
5.4MEDIUM
CVE-2025-51654
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
5.4MEDIUM
CVE-2025-51653
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
5.4MEDIUM
CVE-2025-51652
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
5.4MEDIUM
CVE-2025-25686
<= 5.0
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
9.8CRITICAL
CVE-2024-13193
<= 4.8
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functi
6.3MEDIUM
CVE-2024-53502
all versions
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
3.8LOW
CVE-2024-52725
all versions
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldg
4.9MEDIUM
CVE-2024-46103
all versions
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
9.8CRITICAL
CVE-2024-36801
all versions
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in
5.9MEDIUM
CVE-2024-36800
all versions
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Do
7.5HIGH
CVE-2024-4595
<= 4.8
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function loca
6.3MEDIUM
CVE-2024-32409
all versions
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
7.1HIGH
CVE-2024-30938
all versions
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the S
9.8CRITICAL
CVE-2024-31012
all versions
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensit
9.8CRITICAL
CVE-2024-31010
all versions
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Bann
7.5HIGH
CVE-2024-31009
all versions
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner
6.5MEDIUM
CVE-2024-28405
all versions
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid
7.2HIGH
CVE-2024-25422
all versions
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information vi
9.8CRITICAL
CVE-2023-48864
all versions
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
7.5HIGH
CVE-2023-50563
all versions
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
9.8CRITICAL
CVE-2023-48863
all versions
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses t
7.5HIGH
CVE-2020-23564
all versions
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
7.2HIGH
CVE-2023-37647
all versions
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
9.8CRITICAL
CVE-2020-18432
all versions
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
9.8CRITICAL
CVE-2023-31707
all versions
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
9.8CRITICAL
CVE-2023-30090
all versions
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulner
9.8CRITICAL
CVE-2021-38733
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
9.8CRITICAL
CVE-2021-38732
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
9.8CRITICAL
CVE-2021-38731
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
9.8CRITICAL
CVE-2021-38730
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
9.8CRITICAL
CVE-2021-38729
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
9.8CRITICAL
CVE-2021-38728
all versions
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
6.1MEDIUM
CVE-2021-38217
all versions
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
9.8CRITICAL
CVE-2021-38737
all versions
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
9.8CRITICAL
CVE-2021-38736
all versions
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
9.8CRITICAL
CVE-2021-38734
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
9.8CRITICAL
CVE-2022-2726
all versions
A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manip
6.3MEDIUM
CVE-2020-18081
all versions
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in pl
7.5HIGH
CVE-2020-18078
all versions
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
9.8CRITICAL
CVE-2019-11518
all versions
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_
7.2HIGH
CVE-2018-20017
all versions
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
4.8MEDIUM
CVE-2018-18841
all versions
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
4.8MEDIUM
CVE-2018-18840
all versions
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
5.4MEDIUM
CVE-2018-18783
all versions
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
6.1MEDIUM
CVE-2018-18745
all versions
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
4.8MEDIUM
CVE-2018-18744
all versions
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
4.8MEDIUM
CVE-2018-18743
all versions
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
4.8MEDIUM
CVE-2018-18742
all versions
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
8.8HIGH
CVE-2018-18741
all versions
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
4.8MEDIUM
CVE-2018-18740
all versions
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
4.8MEDIUM
CVE-2018-18739
all versions
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
4.8MEDIUM
CVE-2018-18738
all versions
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
4.8MEDIUM
threatengine.sh