在 SeaCMS 13.6 及更早版本中检测到一个漏洞。该问题影响组件“评论缓存”中文件 的某些未知处理逻辑。对该文件中 和 参数的操纵会导致路径遍历(Path Traversal)漏洞。此攻击可远程发起,且相关利用方式已公开,存在被实际利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | SeaCMS | 13.0 |
cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82608 | 7.4 HIGH | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82600 | 7.3 HIGH | SeaCMS zyapi.php sql injection |
| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82599 | 5.4 MEDIUM | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82602 | 5.3 MEDIUM | SeaCMS ass.php authorization |
| CVE-2026-82601 | 4.3 MEDIUM | SeaCMS err.php cross site scripting |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
No comments yet