Product:

Seacms

(Seacms)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 72
Date Id Summary Products Score Patch Annotated
2024-09-03 CVE-2024-44920 A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter. Seacms 6.1
2024-09-03 CVE-2024-44921 SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del. Seacms 9.8
2018-09-26 CVE-2018-17365 SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter. Seacms 7.5
2019-02-17 CVE-2019-8418 SeaCMS 7.2 mishandles member.php?mod=repsw4 requests. Seacms 8.8
2018-11-17 CVE-2018-19350 In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. Seacms 5.4
2018-11-17 CVE-2018-19349 In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php. Seacms 7.2
2018-09-22 CVE-2018-17321 An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action. Seacms 6.1
2018-09-16 CVE-2018-17062 An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. Seacms 6.1
2018-09-21 CVE-2018-16822 SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. Seacms 9.8
2018-09-21 CVE-2018-16821 SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. Seacms 5.3