Vulnerabilities > SEM CMS > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-10 CVE-2023-48864 SQL Injection vulnerability in Sem-Cms Semcms 4.8
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
network
low complexity
sem-cms CWE-89
7.5
2023-12-04 CVE-2023-48863 SQL Injection vulnerability in Sem-Cms Semcms 3.9
SEMCMS 3.9 is vulnerable to SQL Injection.
network
low complexity
sem-cms CWE-89
7.5
2023-08-05 CVE-2020-23564 Unrestricted Upload of File with Dangerous Type vulnerability in Sem-Cms Semcms 3.9
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
network
low complexity
sem-cms CWE-434
7.2