See how seacms compares to other vendors in security performance
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=delpl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A cross-site scripting (XSS) vulnerability in the component admin Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the adminsafe.php component.
A Cross-Site Request Forgery (CSRF) in adminmanager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminfiles.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminip.php.
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the filegetcontents function at adminsafefile.php.
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the filegetcontents function at adminsafe.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminsmtp.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admintemplate.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminping.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at adminweixin.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminnotify.php.
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in adminnotify.php.
Vulnerability in adminip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admintype.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Seacms <13.3 is vulnerable to SQL Injection in adminpay.php.
Seacms <=13.3 is vulnerable to SQL Injection in admintypenews.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminmembers.php.
Seacms <=13.3 is vulnerable to SQL Injection in admincollectnews.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminpaylog.php.
Seacms <=13.3 is vulnerable to SQL Injection in admincollect.php that allows an authenticated attacker to exploit the database.
Seacms <=13.3 is vulnerable to SQL Injection in adminzyk.php.