Vulnerabilities
Vulnerable Software
Seacms:  Security Vulnerabilities
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CVSS Score
9.8
EPSS Score
0.111
Published
2022-04-27
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVSS Score
9.8
EPSS Score
0.009
Published
2022-03-02
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
CVSS Score
9.8
EPSS Score
0.016
Published
2021-08-18
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
CVSS Score
6.1
EPSS Score
0.002
Published
2021-08-17
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.
CVSS Score
6.5
EPSS Score
0.001
Published
2021-08-17
A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an attacker to inject arbitrary web script or HTML.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-05-28
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
CVSS Score
9.8
EPSS Score
0.11
Published
2020-12-21
SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.
CVSS Score
8.8
EPSS Score
0.004
Published
2019-02-17
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2018-11-17
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-11-17


Contact Us

Shodan ® - All rights reserved