VendorsSemCmssemcms3.8
Vulnerabilities

SemCms Semcms 3.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-18078
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
Published 2021-12-17 · Modified
9.8EPSS 0.010
CVE-2020-18081
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
Published 2021-12-17 · Modified
7.5EPSS 0.011
CVE-2019-11518
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
Published 2019-04-25 · Modified
7.2EPSS 0.013