← Terug naar overzicht

A code injection vulnerability has been identified in SeaCMS up to version 13.6, specifically within the parseIf function in the seacms_locoy_news.php file of the Locoy Collector component. Attackers can manipulate the 'pwd' argument to inject and execute arbitrary code remotely. The vulnerability is remotely exploitable without requiring physical access to the system. A public exploit has been disclosed, increasing the risk of active exploitation in the wild. The affected product is a widely used CMS platform, making this vulnerability potentially high-impact. The issue has been assigned CVE-2026-85137 and is tracked by NVD and VulDB. Users of SeaCMS 13.6 and earlier versions should apply patches or mitigations immediately. The public disclosure of the exploit raises the urgency for defenders to monitor and respond.

Affected products

  • SeaCMS 13.6

Related CVE's

  • CVE-2026-85137

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities