Vulnerabilities
Vulnerable Software
Sem-Cms:  >> Semcms  Security Vulnerabilities
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
6.3
EPSS Score
0.0
Published
2025-01-08
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVSS Score
3.8
EPSS Score
0.0
Published
2024-12-03
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
CVSS Score
4.9
EPSS Score
0.001
Published
2024-11-20
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-09-20
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-06-04
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
CVSS Score
5.9
EPSS Score
0.005
Published
2024-06-04
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263317 was assigned to this vulnerability.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-07
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVSS Score
7.1
EPSS Score
0.016
Published
2024-04-19
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-04-19
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-03


Contact Us

Shodan ® - All rights reserved