CVE-2026-85138: SeaCMS WeChat index.php addslashes sql injection
Published Sep 3, 2026
·Updated
A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
2 affected components
SeaCMS<=13.6
WeChat Module/weixin/index.php
Event History
Sep 3, 2026
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The severity vector indicates no privileges and no user interaction are required, and the attack can be launched remotely.
2
Which deployments are in scope?
SeaCMS versions up to 13.6 are affected where the WeChat Module component at weixin/index.php is present. The vulnerable processing involves the Content argument.
3
How likely is active exploitation?
A public exploit is available and may be used. This increases the practical risk for remotely reachable affected installations.