VendorsSemCmssemcms4.8
Vulnerabilities

SemCms Semcms 4.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-31012
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
Published 2024-04-03 · Analyzed
9.8EPSS 0.012
CVE-2024-25422
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
Published 2024-02-28 · Modified
9.8EPSS 0.010
CVE-2024-30938
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
Published 2024-04-18 · Analyzed
9.8EPSS 0.008
CVE-2023-50563
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
Published 2023-12-14 · Modified
9.8EPSS 0.006
CVE-2024-46103
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
Published 2024-09-20 · Analyzed
9.8EPSS 0.005
CVE-2024-31010
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
Published 2024-04-03 · Analyzed
7.5EPSS 0.008
CVE-2024-36800
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
Published 2024-06-04 · Analyzed
7.5EPSS 0.007
CVE-2023-48864
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
Published 2024-01-10 · Modified
7.5EPSS 0.006
CVE-2024-28405
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
Published 2024-03-29 · Analyzed
7.2EPSS 0.008
CVE-2024-32409
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
Published 2024-04-19 · Modified
7.1EPSS 0.005
CVE-2024-31009
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-36801
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
Published 2024-06-04 · Analyzed
5.9EPSS 0.004
CVE-2024-52725
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
Published 2024-11-20 · Modified
4.9EPSS 0.006
CVE-2024-53502
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
Published 2024-12-03 · Analyzed
3.8EPSS 0.003