Vulnerabilities (CVE)

Filtered by vendor Seacms Subscribe
Total 114 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-4256 1 Seacms 1 Seacms 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-44074 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
CVE-2025-44073 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-44072 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
CVE-2025-44071 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
CVE-2025-3797 1 Seacms 1 Seacms 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3792 1 Seacms 1 Seacms 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-29647 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVE-2025-25521 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2025-25520 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25519 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25517 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
CVE-2025-25516 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-25515 1 Seacms 1 Seacms 2026-06-17 N/A 8.8 HIGH
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2025-25514 1 Seacms 1 Seacms 2026-06-17 N/A 6.5 MEDIUM
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
CVE-2025-25513 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
CVE-2025-22974 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
CVE-2025-15003 1 Seacms 1 Seacms 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performing a manipulation of the argument e_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2025-15002 1 Seacms 1 Seacms 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11071 1 Seacms 1 Seacms 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of the component Cron Task Management Module. The manipulation of the argument resourcefrom/collectID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.