A critical code injection vulnerability has been identified in SeaCMS versions up to 13.6. The vulnerability resides in the parseIf function within search.php, part of the Template Engine component. Attackers can manipulate the 'searchtype' argument to inject and execute arbitrary code remotely. The exploit has been publicly disclosed on GitHub, increasing the risk of widespread exploitation. No authentication appears to be required to exploit this vulnerability remotely. The affected product is SeaCMS, a popular Chinese content management system. The public availability of a proof-of-concept exploit makes this a high-priority patching target for affected installations.