Show filters
142 Total Results
Displaying 31-40 of 142
Sort by:
Attacker Value
Unknown

CVE-2023-48864

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
Attacker Value
Unknown

CVE-2023-50470

Disclosure Date: December 28, 2023 (last updated February 25, 2025)
A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2023-46987

Disclosure Date: December 28, 2023 (last updated February 25, 2025)
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
Attacker Value
Unknown

CVE-2023-50563

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
Attacker Value
Unknown

CVE-2023-48863

Disclosure Date: December 04, 2023 (last updated February 25, 2025)
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.
Attacker Value
Unknown

CVE-2023-46010

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
Attacker Value
Unknown

CVE-2023-44848

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.
Attacker Value
Unknown

CVE-2023-44847

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
Attacker Value
Unknown

CVE-2023-44846

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
Attacker Value
Unknown

CVE-2023-44172

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.