Product
sem cms semcms
59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1552
CVE-2025-51660
CVE-2025-51659
CVE-2025-51658
CVE-2025-51657
CVE-2025-51656
CVE-2025-51655
CVE-2025-51654
CVE-2025-51653
CVE-2025-51652
CVE-2025-25686
CVE-2024-13193
CVE-2024-53502
CVE-2024-52725
CVE-2024-46103
CVE-2024-36801
CVE-2024-36800
CVE-2024-4595
CVE-2024-32409
CVE-2024-30938
CVE-2024-31012
CVE-2024-31010
CVE-2024-31009
CVE-2024-28405
CVE-2024-25422
CVE-2023-48864
CVE-2023-50563
CVE-2023-48863
CVE-2020-23564
CVE-2023-37647
CVE-2020-18432
CVE-2023-31707
CVE-2023-30090
CVE-2021-38733
CVE-2021-38732
CVE-2021-38731
CVE-2021-38730
CVE-2021-38729
CVE-2021-38728
CVE-2021-38217
CVE-2021-38737
CVE-2021-38736
CVE-2021-38734
CVE-2022-2726
CVE-2020-18081
CVE-2020-18078
CVE-2019-11518
CVE-2018-20017
CVE-2018-18841
CVE-2018-18840
CVE-2018-18783
CVE-2018-18745
CVE-2018-18744
CVE-2018-18743
CVE-2018-18742
CVE-2018-18741
CVE-2018-18740
CVE-2018-18739
CVE-2018-18738
all versions
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. Th
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
<= 5.0
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
<= 5.0
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
<= 4.8
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functi
all versions
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
all versions
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldg
all versions
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
all versions
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in
all versions
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Do
<= 4.8
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function loca
all versions
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
all versions
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the S
all versions
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensit
all versions
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Bann
all versions
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner
all versions
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid
all versions
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information vi
all versions
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
all versions
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
all versions
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses t
all versions
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
all versions
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
all versions
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
all versions
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
all versions
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulner
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
all versions
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
all versions
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
all versions
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
all versions
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
all versions
A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manip
all versions
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in pl
all versions
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
all versions
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_
all versions
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
all versions
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
all versions
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
all versions
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
all versions
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
all versions
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
all versions
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
all versions
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
all versions
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
all versions
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
all versions
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
all versions
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.