VendorsSemCmssemcmsall versions
Vulnerabilities

SemCms Semcms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

59CVEs
CVE-2024-31012
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
Published 2024-04-03 · Analyzed
9.8EPSS 0.012
CVE-2024-25422
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
Published 2024-02-28 · Modified
9.8EPSS 0.010
CVE-2020-18078
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
Published 2021-12-17 · Modified
9.8EPSS 0.010
CVE-2020-18432
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
Published 2023-06-30 · Modified
9.8EPSS 0.009
CVE-2021-38730
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38736
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38729
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38737
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38734
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38732
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2021-38217
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
Published 2022-10-28 · Modified
9.8EPSS 0.008
CVE-2023-30090
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
Published 2023-05-05 · Modified
9.8EPSS 0.008
CVE-2024-30938
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
Published 2024-04-18 · Analyzed
9.8EPSS 0.008
CVE-2023-31707
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
Published 2023-05-19 · Modified
9.8EPSS 0.008
CVE-2022-2726
SEMCMS Ant_Check.php sql injection
Published 2022-08-09 · Modified
9.8EPSS 0.007
CVE-2021-38731
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
Published 2022-10-28 · Modified
9.8EPSS 0.007
CVE-2021-38733
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
Published 2022-10-28 · Modified
9.8EPSS 0.007
CVE-2023-50563
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
Published 2023-12-14 · Modified
9.8EPSS 0.006
CVE-2023-37647
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Published 2023-07-31 · Modified
9.8EPSS 0.006
CVE-2024-46103
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
Published 2024-09-20 · Analyzed
9.8EPSS 0.005
CVE-2025-25686
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
Published 2025-03-27 · Analyzed
9.8EPSS 0.005
CVE-2026-1552
SEMCMS SEMCMS_Info.php sql injection
Published 2026-01-29 · Analyzed
9.8EPSS 0.004
CVE-2018-18742
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
Published 2018-10-28 · Modified
8.8EPSS 0.005
CVE-2020-18081
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
Published 2021-12-17 · Modified
7.5EPSS 0.011
CVE-2023-48863
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.
Published 2023-12-04 · Modified
7.5EPSS 0.009
CVE-2024-31010
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
Published 2024-04-03 · Analyzed
7.5EPSS 0.008
CVE-2024-36800
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
Published 2024-06-04 · Analyzed
7.5EPSS 0.007
CVE-2023-48864
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
Published 2024-01-10 · Modified
7.5EPSS 0.006
CVE-2019-11518
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
Published 2019-04-25 · Modified
7.2EPSS 0.013
CVE-2020-23564
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
Published 2023-08-05 · Modified
7.2EPSS 0.011
CVE-2024-28405
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
Published 2024-03-29 · Analyzed
7.2EPSS 0.008
CVE-2024-32409
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
Published 2024-04-19 · Modified
7.1EPSS 0.005
CVE-2024-31009
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-4595
SEMCMS function.php locate sql injection
Published 2024-05-07 · Analyzed
6.5EPSS 0.006
CVE-2024-13193
SEMCMS Image Library Management Page SEMCMS_Images.php sql injection
Published 2025-01-08 · Analyzed
6.5EPSS 0.005
CVE-2018-18783
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
Published 2018-10-29 · Modified
6.1EPSS 0.008
CVE-2021-38728
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
Published 2022-10-28 · Modified
6.1EPSS 0.005
CVE-2024-36801
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
Published 2024-06-04 · Analyzed
5.9EPSS 0.004
CVE-2018-18840
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
Published 2018-10-30 · Modified
5.4EPSS 0.006
CVE-2025-51655
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
Published 2025-07-14 · Modified
5.4EPSS 0.002
1 / 2Next →