Sem-cms
Sem-cms Semcms: vulnerabilidades y CVE
Sem-cms Semcms tiene 62 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 21 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses4
Críticas21
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96739 | Baja (2.1) | 0.26% | — | 24 sept 2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument… |
| CVE-2026-39170 | Media (6.3) | 0.15% | — | 9 jun 2026 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. |
| CVE-2026-39169 | Alta (7.5) | 0.39% | — | 9 jun 2026 | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. |
| CVE-2026-1552 | Baja (2.1) | 0.38% | — | 29 ene 2026 | A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to… |
| CVE-2025-51660 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. |
| CVE-2025-51659 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. |
| CVE-2025-51658 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. |
| CVE-2025-51657 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. |
| CVE-2025-51656 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. |
| CVE-2025-51655 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. |
| CVE-2025-51654 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. |
| CVE-2025-51653 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. |
| CVE-2025-51652 | Media (5.4) | 0.23% | — | 14 jul 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. |
| CVE-2025-25686 | Crítica (9.8) | 0.50% | — | 27 mar 2025 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. |
| CVE-2024-13193 | Media (5.3) | 0.51% | — | 8 ene 2025 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The… |
| CVE-2024-53502 | Baja (3.8) | 0.29% | — | 3 dic 2024 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. |
| CVE-2024-52725 | Media (4.9) | 0.55% | — | 20 nov 2024 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component. |
| CVE-2024-46103 | Crítica (9.8) | 0.51% | — | 20 sept 2024 | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. |
| CVE-2024-36801 | Media (5.9) | 0.39% | — | 4 jun 2024 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php. |
| CVE-2024-36800 | Alta (7.5) | 0.70% | — | 4 jun 2024 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php. |
| CVE-2024-4595 | Media (6.5) | 0.57% | — | 7 may 2024 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be… |
| CVE-2024-32409 | Alta (7.1) | 0.47% | — | 19 abr 2024 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. |
| CVE-2024-30938 | Crítica (9.8) | 0.76% | — | 19 abr 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. |
| CVE-2024-31012 | Crítica (9.8) | 1.2% | — | 3 abr 2024 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file. |
| CVE-2024-31010 | Alta (7.5) | 0.79% | — | 3 abr 2024 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php. |
| CVE-2024-31009 | Media (6.5) | 0.74% | — | 3 abr 2024 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php. |
| CVE-2024-28405 | Alta (7.2) | 0.80% | — | 29 mar 2024 | SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain… |
| CVE-2024-25422 | Crítica (9.8) | 1.0% | — | 28 feb 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component. |
| CVE-2023-48864 | Alta (7.5) | 0.61% | — | 10 ene 2024 | SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php. |
| CVE-2023-50563 | Crítica (9.8) | 0.63% | — | 14 dic 2023 | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. |