Vulnerabilities > Seacms > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-25 CVE-2023-43278 Cross-Site Request Forgery (CSRF) vulnerability in Seacms
A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
network
low complexity
seacms CWE-352
8.8
2023-02-01 CVE-2022-48093 Code Injection vulnerability in Seacms 12.7
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
network
low complexity
seacms CWE-94
7.2
2022-03-02 CVE-2022-23878 Unspecified vulnerability in Seacms 11.5
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
network
low complexity
seacms
7.5
2021-08-18 CVE-2021-37358 SQL Injection vulnerability in Seacms 20210530
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
network
low complexity
seacms CWE-89
7.5
2020-12-21 CVE-2020-21378 SQL Injection vulnerability in Seacms 10.1
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
network
low complexity
seacms CWE-89
7.5
2018-09-21 CVE-2018-16822 SQL Injection vulnerability in Seacms 6.64
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
network
low complexity
seacms CWE-89
7.5
2018-09-04 CVE-2018-16445 SQL Injection vulnerability in Seacms
An issue was discovered in SeaCMS through 6.61.
network
low complexity
seacms CWE-89
7.5