Vulnerabilities (CVE)

Filtered by vendor Seacms Subscribe
Filtered by product Seacms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27336 1 Seacms 1 Seacms 2023-08-08 7.5 HIGH 9.8 CRITICAL
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CVE-2021-37358 1 Seacms 1 Seacms 2021-08-28 7.5 HIGH 9.8 CRITICAL
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
CVE-2020-21378 1 Seacms 1 Seacms 2020-12-22 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
CVE-2018-16822 1 Seacms 1 Seacms 2018-11-07 7.5 HIGH 9.8 CRITICAL
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVE-2018-16444 1 Seacms 1 Seacms 2018-10-25 6.4 MEDIUM 9.1 CRITICAL
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
CVE-2018-16445 1 Seacms 1 Seacms 2018-10-25 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.