📦 Seacms

by Seacms

🔍 What is Seacms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-44073

CRITICAL CVSS 9.8 May 6, 2025

SeaCMS v13.3 contains a SQL injection vulnerability in the admin_comment_news.php component that allows attackers to execute arbitrary SQL commands. This affects all SeaCMS v13.3 installations with th...

CVE-2025-44074

CRITICAL CVSS 9.8 May 5, 2025

SeaCMS v13.3 contains a SQL injection vulnerability in the admin_topic.php component that allows attackers to execute arbitrary SQL commands. This affects all SeaCMS v13.3 installations with the vulne...

CVE-2025-44071

CRITICAL CVSS 9.8 May 5, 2025

SeaCMS v13.3 contains a remote code execution vulnerability in phomebak.php that allows attackers to execute arbitrary code via crafted HTTP requests. This affects all SeaCMS v13.3 installations with ...

CVE-2025-25516

CRITICAL CVSS 9.8 Feb 25, 2025

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_paylog.php that allows attackers to execute arbitrary SQL commands. This affects all Seacms installations running vulnerable v...

CVE-2025-25519

CRITICAL CVSS 9.8 Feb 25, 2025

SeaCMS versions up to 13.3 contain a SQL injection vulnerability in the admin_zyk.php file that allows attackers to execute arbitrary SQL commands. This affects all SeaCMS installations running vulner...

CVE-2025-25521

CRITICAL CVSS 9.8 Feb 25, 2025

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_type_news.php that allows attackers to execute arbitrary SQL commands. This affects all Seacms installations running vulnerabl...

CVE-2025-22974

CRITICAL CVSS 9.8 Feb 24, 2025

This SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through the DoTranExecSql parameter in phome.php. Attackers can potentially read, modify, or delete...

CVE-2025-25513

CRITICAL CVSS 9.8 Feb 24, 2025

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_members.php that allows attackers to execute arbitrary SQL commands. This affects all Seacms installations running vulnerable ...

CVE-2024-54880

CRITICAL CVSS 9.1 Jan 6, 2025

SeaCMS V13.1 contains an incorrect access control vulnerability that allows attackers to bypass registration limits and create accounts in bulk. This affects all SeaCMS V13.1 installations with user r...

CVE-2024-55461

CRITICAL CVSS 9.8 Dec 18, 2024

SeaCMS versions up to 13.0 contain a command injection vulnerability in phome.php through the Ebak_RepPathFiletext() function. This allows attackers to execute arbitrary commands on the server with th...

CVE-2024-46640

CRITICAL CVSS 9.8 Sep 20, 2024

SeaCMS 13.2 contains a remote code execution vulnerability in sql.class.chp where a security check function is bypassed during execution. Attackers can exploit this by writing malicious code through M...

CVE-2024-44721

CRITICAL CVSS 9.8 Sep 9, 2024

SeaCMS v13.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /admin_reslib.php file via the url parameter. This allows attackers to make arbitrary HTTP requests from the vulnerable ...

CVE-2024-44921

CRITICAL CVSS 9.8 Sep 3, 2024

SeaCMS v12.9 contains a SQL injection vulnerability in the id parameter at /dmplayer/dmku/index.php?ac=del. This allows attackers to execute arbitrary SQL commands on the database. All SeaCMS v12.9 in...

CVE-2024-39028

CRITICAL CVSS 9.8 Jul 5, 2024

This vulnerability in SeaCMS allows remote attackers to execute arbitrary code via the admin_ping.php file. It affects SeaCMS versions up to and including 12.9, enabling complete system compromise of ...

CVE-2024-29275

CRITICAL CVSS 9.8 Mar 22, 2024

This critical SQL injection vulnerability in SeaCMS version 12.9 allows unauthenticated attackers to execute arbitrary SQL commands via the id parameter. Attackers can potentially read, modify, or del...

CVE-2023-46010

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability in SeaCMS v12.9 allows remote attackers to execute arbitrary commands through the admin_safe.php component. This is a critical remote code execution flaw affecting all SeaCMS v12.9 ...

CVE-2023-44169

CRITICAL CVSS 9.8 Sep 27, 2023

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_notify.php that allows attackers to write malicious files to the server. This affects all SeaCMS V12.9 installations with the admin...

CVE-2023-44171

CRITICAL CVSS 9.8 Sep 27, 2023

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_smtp.php that allows attackers to write malicious files to the server. This affects all SeaCMS V12.9 installations with the vulnera...

CVE-2023-43216

CRITICAL CVSS 9.8 Sep 27, 2023

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_ip.php that allows attackers to write malicious files to the server. This affects all SeaCMS V12.9 installations with the vulnerabl...

CVE-2022-27336

CRITICAL CVSS 9.8 Apr 27, 2022

CVE-2022-27336 is a remote code execution vulnerability in Seacms v11.6 that allows attackers to execute arbitrary code via the /admin/weixin.php component. This affects all systems running the vulner...

CVE-2025-15002

HIGH CVSS 7.3 Dec 21, 2025

This SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through manipulated page/limit parameters in the dmplayer component. It affects all SeaCMS installa...

CVE-2025-25515

HIGH CVSS 8.8 Feb 25, 2025

Seacms versions up to 13.3 contain a SQL injection vulnerability in admin_collect.php that allows authenticated attackers to execute arbitrary SQL commands against the database. This affects all Seacm...

CVE-2024-50808

HIGH CVSS 8.8 Nov 8, 2024

SeaCms 13.1 contains a code injection vulnerability in the admin notification module that allows authenticated backend users to execute arbitrary code. This affects administrators with access to the b...

CVE-2024-44720

HIGH CVSS 7.5 Sep 9, 2024

SeaCMS v13.1 contains an arbitrary file read vulnerability in admin_safe.php that allows attackers to read sensitive files on the server. This affects all SeaCMS v13.1 installations with the vulnerabl...

CVE-2024-44916

HIGH CVSS 7.2 Aug 30, 2024

This vulnerability in Seacms v13.1 allows attackers to inject malicious IP parameters through the admin_ip.php file, which are then written to a configuration file and can lead to arbitrary command ex...

CVE-2024-42599

HIGH CVSS 8.8 Aug 22, 2024

SeaCMS 13.0 contains a remote code execution vulnerability in admin_files.php where authenticated attackers can bypass file editing restrictions to write and execute arbitrary code. This allows attack...

CVE-2024-40522

HIGH CVSS 8.8 Jul 12, 2024

SeaCMS 12.9 contains a remote code execution vulnerability in phomebak.php where unfiltered variable names are written into PHP files. Authenticated attackers can exploit this to execute arbitrary com...

CVE-2024-40518

HIGH CVSS 8.8 Jul 12, 2024

SeaCMS 12.9 contains a remote code execution vulnerability in admin_weixin.php where unvalidated user input is directly written to weixin.php. Authenticated attackers can exploit this to execute arbit...

CVE-2024-40520

HIGH CVSS 8.8 Jul 12, 2024

SeaCMS 12.9 has a remote code execution vulnerability in admin_config_mark.php that allows authenticated attackers to inject arbitrary code into inc_photowatermark_config.php. This enables attackers t...

CVE-2024-30565

HIGH CVSS 8.8 Apr 4, 2024

SeaCMS version 12.9 contains a vulnerability in admin/notify.php that allows remote attackers to execute arbitrary code. This is a code injection vulnerability (CWE-94) that affects all SeaCMS 12.9 in...

CVE-2023-46987

HIGH CVSS 8.8 Dec 28, 2023

SeaCMS v12.9 contains a remote code execution vulnerability in the /augap/adminip.php component that allows attackers to execute arbitrary code on affected servers. This affects all SeaCMS v12.9 insta...

CVE-2023-44847

HIGH CVSS 7.2 Oct 10, 2023

This vulnerability in SeaCMS v12.8 allows attackers to execute arbitrary code through the admin_Weixin.php component. It affects all systems running the vulnerable version of SeaCMS, potentially compr...

CVE-2023-43278

HIGH CVSS 8.8 Sep 25, 2023

This CSRF vulnerability in Seacms allows attackers to create unauthorized admin accounts by tricking authenticated administrators into visiting malicious web pages. It affects Seacms installations up ...

CVE-2025-15003

MEDIUM CVSS 4.7 Dec 22, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against SeaCMS versions up to 13.3 through manipulation of the e_id parameter in admin_video.php. Attackers can potentially ...

CVE-2025-60449

MEDIUM CVSS 4.9 Oct 3, 2025

An information disclosure vulnerability in SeaCMS 13.1 allows authenticated administrators to scan and download files from the server's root directory via the admin_safe.php component. This affects Se...

CVE-2025-10662

MEDIUM CVSS 4.7 Sep 18, 2025

This SQL injection vulnerability in SeaCMS allows attackers to manipulate database queries through the /admin_members.php endpoint. Attackers can potentially read, modify, or delete database content. ...

CVE-2024-40570

MEDIUM CVSS 6.5 Jun 17, 2025

This CVE describes an SQL injection vulnerability in SeaCMS v.12.9 that allows a remote attacker to execute arbitrary SQL commands via the admin_datarelate.php component. This can lead to unauthorized...

CVE-2025-3797

MEDIUM CVSS 4.7 Apr 19, 2025

This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands via the e_id parameter in the /admin_topic.php?action=delall endpoint. Attackers can poten...

CVE-2025-3792

MEDIUM CVSS 4.7 Apr 18, 2025

This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through the /admin_link.php endpoint. Attackers can potentially read, modify, or delete da...

CVE-2025-25802

MEDIUM CVSS 5.1 Feb 26, 2025

SeaCMS v13.3 contains a remote code execution vulnerability in the admin_ip.php component that allows attackers to execute arbitrary code on affected systems. This affects all SeaCMS v13.3 installatio...

CVE-2025-25793

MEDIUM CVSS 5.1 Feb 26, 2025

SeaCMS v13.3 contains a remote code execution vulnerability in the admin_notify.php component that allows attackers to execute arbitrary code on affected systems. This affects all SeaCMS v13.3 install...

CVE-2025-25796

MEDIUM CVSS 5.1 Feb 26, 2025

SeaCMS v13.3 contains a remote code execution vulnerability in admin_template.php that allows attackers to execute arbitrary code on affected systems. This affects all SeaCMS v13.3 installations with ...

CVE-2025-25799

MEDIUM CVSS 6.0 Feb 26, 2025

SeaCMS 13.3 contains an arbitrary file read vulnerability in the admin_safe.php file that allows attackers to read sensitive files on the server. This affects all SeaCMS 13.3 installations with defaul...

CVE-2025-25514

MEDIUM CVSS 6.5 Feb 25, 2025

This SQL injection vulnerability in Seacms allows attackers to execute arbitrary SQL commands through the admin_collect_news.php endpoint. It affects Seacms version 13.3 and earlier, potentially compr...

CVE-2024-44920

MEDIUM CVSS 6.1 Sep 3, 2024

This is a cross-site scripting (XSS) vulnerability in SeaCMS v12.9 that allows attackers to inject malicious scripts into the admin_collect_news.php component via the siteurl parameter. Attackers can ...

CVE-2024-44683

MEDIUM CVSS 6.1 Aug 30, 2024

Seacms v13 contains a cross-site scripting vulnerability in admin-video.php that allows attackers to inject malicious scripts into web pages viewed by administrators. This affects administrators of Se...

CVE-2024-44919

MEDIUM CVSS 5.4 Aug 29, 2024

This is a cross-site scripting (XSS) vulnerability in SeaCMS v12.9's admin_ads.php component that allows attackers to inject malicious scripts into ad descriptions. When exploited, it enables executio...

CVE-2024-42598

MEDIUM CVSS 6.7 Aug 20, 2024

SeaCMS 13.0 has an authenticated remote code execution vulnerability in admin_editplayer.php where attackers can bypass file restrictions to write and execute arbitrary code. This allows authenticated...

CVE-2024-7161

MEDIUM CVSS 4.3 Jul 28, 2024

This CSRF vulnerability in SeaCMS 13.0 allows attackers to trick authenticated users into changing their passwords without their consent by manipulating the password change form. Attackers can launch ...