See how seacms compares to other vendors in security performance
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via adminping.php.
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /adminreslib.php.
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function EbakRepPathFiletext().
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
Seacms <=13.3 is vulnerable to SQL Injection in adminmembers.php.
Seacms <13.3 is vulnerable to SQL Injection in adminpay.php.
Seacms <=13.3 is vulnerable to SQL Injection in admintypenews.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminpaylog.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminzyk.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminreslib.php.
SeaCMS v13.3 has a SQL injection vulnerability in the component admintempvideo.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component adminmanager.php.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admintopic.php.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admincommentnews.php.
A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /adminmembers.php?ac=editsave. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This affects another injection point than CVE-2025-25513.
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminip.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminping.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminweixin.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminnotify.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminsmtp.php.
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/adminping.php file.
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-221630 is the identifier assigned to this vulnerability.
SeaCMS 6.64 allows SQL Injection via the upload/admin/adminvideo.php order parameter.
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to adminmembersgroup.php.