SeaCMS 6.64 allows SQL Injection via the upload/admin/adminvideo.php order parameter.
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
In SeaCMS v6.64, there is SQL injection via the adminmakehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
An issue was discovered in SeaCMS 6.64. XSS exists in admindatarelate.php via the time or maxHit parameter in a dorandomset action.
An issue was discovered in SeaCMS 6.64. XSS exists in adminvideo.php via the action, area, type, yuyan, jqtype, visunion, vrecycled, vismoney, or vispsd parameter.
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admintemplate.php?path=../templets/../../ requests.