← Terug naar overzicht

A SQL injection vulnerability has been identified in SeaCMS up to version 13.6, specifically within the WeChat Module component. The vulnerability exists in the addslashes function located in the file weixin/index.php. Attackers can manipulate the 'Content' argument to perform SQL injection attacks remotely. The vulnerability is publicly disclosed and a working exploit is available, increasing the risk of active exploitation. No authentication details are specified, suggesting the attack surface may be broad. The affected software is SeaCMS, a content management system. The public availability of the exploit makes this a high-priority issue for administrators running affected versions. Users are advised to update or apply mitigations immediately to prevent unauthorized database access or manipulation.

Affected products

  • SeaCMS 13.6

Related CVE's

  • CVE-2026-85138

Categories

  • Database & Storage
  • Web Technologies