📦 Semcms

by Sem Cms

🔍 What is Semcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-25686

CRITICAL CVSS 9.8 Mar 27, 2025

This vulnerability allows attackers to execute arbitrary SQL commands through SEMCMS_Fuction.php in SEMCMS versions up to 5.0. Attackers can potentially access, modify, or delete database content. All...

CVE-2024-30938

CRITICAL CVSS 9.8 Apr 19, 2024

This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to extract sensitive database information by manipulating the ID parameter in SEMCMS_User.php. Any organization using the vulner...

CVE-2024-31012

CRITICAL CVSS 9.8 Apr 3, 2024

This vulnerability in SEMCMS v4.8 allows remote attackers to upload malicious files via upload.php, leading to arbitrary code execution, privilege escalation, and sensitive information disclosure. Any...

CVE-2024-25422

CRITICAL CVSS 9.8 Feb 28, 2024

This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to execute arbitrary SQL commands through the SEMCMS_Menu.php component. Attackers can potentially read, modify, or delete datab...

CVE-2020-18432

CRITICAL CVSS 9.8 Jun 30, 2023

CVE-2020-18432 is a critical file upload vulnerability in SEMCMS PHP 3.7 that allows remote attackers to upload arbitrary files, including web shells, to gain escalated privileges and potentially achi...

CVE-2023-31707

CRITICAL CVSS 9.8 May 19, 2023

CVE-2023-31707 is a critical SQL injection vulnerability in SEMCMS 1.5 that allows attackers to execute arbitrary SQL commands via the Ant_Rponse.php file. This affects all websites running SEMCMS 1.5...

CVE-2020-18078

CRITICAL CVSS 9.8 Dec 17, 2021

This vulnerability in SEMCMS v3.8 allows unauthenticated attackers to reset the administrator password via a flaw in /include/web_check.php. Attackers can gain administrative access to the CMS, affect...

CVE-2024-32409

HIGH CVSS 7.1 Apr 19, 2024

This vulnerability in SEMCMS v4.8 allows remote attackers to execute arbitrary code by uploading or injecting crafted scripts. It affects all users running SEMCMS v4.8, potentially compromising websit...

CVE-2024-31010

HIGH CVSS 7.5 Apr 3, 2024

This SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to extract sensitive information from the database by manipulating the ID parameter in Banner.php. All websites running SEMCMS v...

CVE-2023-48864

HIGH CVSS 7.5 Jan 10, 2024

SEMCMS v4.8 contains a SQL injection vulnerability in the languageID parameter of /web_inc.php that allows attackers to execute arbitrary SQL commands. This affects all SEMCMS v4.8 installations using...

CVE-2023-48863

HIGH CVSS 7.5 Dec 4, 2023

CVE-2023-48863 is an SQL injection vulnerability in SEMCMS 3.9 that allows attackers to execute arbitrary SQL commands through the application. This affects all SEMCMS 3.9 installations where user inp...

CVE-2026-1552

MEDIUM CVSS 6.3 Jan 29, 2026

This SQL injection vulnerability in SEMCMS 5.0 allows attackers to manipulate database queries through the searchml parameter in /SEMCMS_Info.php. Attackers can potentially read, modify, or delete dat...

CVE-2025-51655

MEDIUM CVSS 5.4 Jul 14, 2025

SemCms v5.0 contains a SQL injection vulnerability in the SEMCMS_Quanxian.php file via the pid parameter. This allows attackers to execute arbitrary SQL commands on the database. All users running Sem...

CVE-2025-51657

MEDIUM CVSS 5.4 Jul 14, 2025

SemCms v5.0 contains a SQL injection vulnerability in the SEMCMS_Link.php file through the lgid parameter. This allows attackers to execute arbitrary SQL commands on the database. All users running Se...

CVE-2025-51659

MEDIUM CVSS 5.4 Jul 14, 2025

SemCms v5.0 contains a SQL injection vulnerability in the ID parameter of SEMCMS_Products.php. This allows attackers to execute arbitrary SQL commands on the database. Users running SemCms v5.0 are af...

CVE-2025-51653

MEDIUM CVSS 5.4 Jul 14, 2025

This SQL injection vulnerability in SemCms v5.0 allows attackers to manipulate database queries through the pid parameter in SEMCMS_ct.php. It affects all users running the vulnerable version of SemCm...

CVE-2024-13193

MEDIUM CVSS 6.3 Jan 8, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the SEMCMS_Images.php file in SEMCMS's Image Library Management Page. It affects all SEMCMS installations up to version...

CVE-2024-52725

MEDIUM CVSS 4.9 Nov 20, 2024

SemCms v4.8 contains a SQL injection vulnerability in the SEMCMS_SeoAndTag.php component via the ldgid parameter. This allows attackers to execute arbitrary SQL commands, potentially leading to data t...

CVE-2024-36801

MEDIUM CVSS 5.9 Jun 4, 2024

A SQL injection vulnerability in SEMCMS v4.8 allows remote attackers to extract sensitive information from the database by manipulating the lgid parameter in Download.php. This affects all SEMCMS v4.8...