A SQL injection vulnerability has been identified in SeaCMS versions up to 13.6. The flaw exists in the /zyapi.php?ac=videolist endpoint, where manipulation of the 'ids' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been released, increasing the risk of active exploitation. The issue affects an unknown functionality within the specified file. The vulnerability has been catalogued under CVE-2026-82600 and documented across NVD and VulDB. No authentication details are specified, suggesting it may be exploitable without credentials. Organizations using SeaCMS 13.6 or earlier should apply mitigations promptly given the public exploit availability.