Filtered by vendor Seacms Subscriptions
Total 107 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-13444 1 Seacms 1 Seacms 2024-11-21 N/A
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.
CVE-2018-12431 1 Seacms 1 Seacms 2024-11-21 N/A
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
CVE-2018-11583 1 Seacms 1 Seacms 2024-11-21 N/A
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
CVE-2024-44919 1 Seacms 1 Seacms 2024-09-06 5.4 Medium
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
CVE-2024-41444 1 Seacms 1 Seacms 2024-09-05 9.8 Critical
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
CVE-2024-44921 1 Seacms 1 Seacms 2024-09-04 9.8 Critical
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
CVE-2024-44920 1 Seacms 1 Seacms 2024-09-04 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.