Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SeaCMS — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in SeaCMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities specifically affecting SeaCMS, focusing on distinct weakness types and associated product tags. It collects a comprehensive range of defects, including memory corruption, cross-site scripting, and privilege escalation issues, covering advisories disclosed from the software’s initial public release through recent updates. Readers can use this resource to track the vendor’s advisory history, understand the technical nature of specific weakness classes, and review the complete vulnerability timeline for the product. The entries are organized to facilitate rapid identification of recurring patterns and to support both security researchers and system administrators in assessing risk exposure. Each record links to detailed technical descriptions, affected versions, and available patches, ensuring users can evaluate the severity of each issue without navigating external databases. This centralized view helps in planning remediation strategies by highlighting which vulnerabilities remain unpatched in the latest stable release. The data is maintained continuously as new advisories are published, providing a reliable snapshot of the product’s current security posture.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-85138 SeaCMS WeChat index.php addslashes sql injection CWE-89 7.3 High 2026-09-03
CVE-2026-85137 SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection CWE-94 7.3 High 2026-09-03
CVE-2026-82603 SeaCMS Comment Cache member.php del_pl path traversal CWE-22 5.4 Medium 2026-08-31
CVE-2026-82602 SeaCMS ass.php authorization CWE-639 5.3 Medium 2026-08-31
CVE-2026-82601 SeaCMS err.php cross site scripting CWE-79 4.3 Medium 2026-08-31
CVE-2026-82600 SeaCMS zyapi.php sql injection CWE-89 7.3 High 2026-08-31
CVE-2026-82599 SeaCMS Avatar Upload member.php unlink path traversal CWE-22 5.4 Medium 2026-08-31
CVE-2026-82598 SeaCMS Template search.php parseIf code injection CWE-94 7.3 High 2026-08-31
CVE-2020-36932 Seacms 11.1 - 'checkuser' Stored XSS CWE-79 6.1 Medium 2026-01-25
CVE-2025-15003 SeaCMS admin_video.php sql injection CWE-89 4.7 Medium 2025-12-21
CVE-2025-15002 SeaCMS mysqli.class.php sql injection CWE-89 7.3 High 2025-12-21
CVE-2025-11071 SeaCMS Cron Task Management admin_cron.php sql injection CWE-89 4.7 Medium 2025-09-27
CVE-2025-10662 SeaCMS admin_members.php sql injection CWE-89 4.7 Medium 2025-09-18
CVE-2025-6864 SeaCMS admin_type.php cross-site request forgery CWE-352 4.3 Medium 2025-06-29
CVE-2025-4257 SeaCMS admin_pay.php cross site scripting CWE-79 3.5 Low 2025-05-05
CVE-2025-4256 SeaCMS admin_paylog.php cross site scripting CWE-79 3.5 Low 2025-05-05
CVE-2025-3797 SeaCMS admin_topic.php sql injection CWE-89 4.7 Medium 2025-04-19
CVE-2025-3792 SeaCMS admin_link.php sql injection CWE-89 4.7 Medium 2025-04-18
CVE-2024-7163 SeaCMS index.php cross site scripting CWE-79 3.5 Low 2024-07-28
CVE-2024-7162 SeaCMS cross site scripting CWE-79 3.5 Low 2024-07-28
CVE-2024-7161 SeaCMS Password Change cross-site request forgery CWE-352 4.3 Medium 2024-07-28
CVE-2024-6416 SeaCMS sql injection CWE-89 6.3 Medium 2024-06-30
CVE-2023-2926 SeaCMS Picture Upload member.php denial of service CWE-404 5.4 Medium 2023-05-27
CVE-2023-0960 SeaCMS Picture Management config.ftp.php deserialization CWE-502 4.7 Medium 2023-02-22

All 24 known CVE vulnerabilities affecting SeaCMS with full Chinese analysis, references, and POCs where available.