在SeaCMS 13.6 及之前版本中发现了一个安全漏洞。受此问题影响的是 文件中某个未知功能模块。通过操纵参数 可以引发 SQL 注入漏洞。该攻击可远程发起。利用程序(exploit)已公开,可被用于实际攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | SeaCMS | 13.0 |
cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82608 | 7.4 HIGH | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82603 | 5.4 MEDIUM | SeaCMS Comment Cache member.php del_pl path traversal |
| CVE-2026-82599 | 5.4 MEDIUM | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82602 | 5.3 MEDIUM | SeaCMS ass.php authorization |
| CVE-2026-82601 | 4.3 MEDIUM | SeaCMS err.php cross site scripting |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
No comments yet