Medium
CVSS: 5.3
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
Medium
CVSS: 6.0
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
Medium
CVSS: 5.1
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
Medium
CVSS: 5.1
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
Medium
CVSS: 5.1
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
Medium
CVSS: 5.1
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
Medium
CVSS: 4.4
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.
Critical
CVSS: 9.8
Seacms
Critical
CVSS: 9.8
Seacms
Critical
CVSS: 9.8
Seacms
Critical
CVSS: 9.8
Seacms
Critical
CVSS: 9.8
Seacms
High
CVSS: 8.8
Seacms
Medium
CVSS: 6.5
Seacms
Critical
CVSS: 9.8
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
Critical
CVSS: 9.8
Seacms
Critical
CVSS: 9.1
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Critical
CVSS: 9.1
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.