← Terug naar overzicht

A code injection vulnerability has been identified in SeaCMS up to version 13.6, specifically within the parseIf function of the seacms_locoy_news.php file in the Locoy Collector component. The vulnerability is triggered by manipulating the 'pwd' argument, allowing an attacker to inject and execute arbitrary code. The attack can be initiated remotely without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. This vulnerability poses a significant threat to systems running affected versions of SeaCMS. The issue has been assigned CVE-2026-85137 and is tracked across multiple vulnerability databases including NVD and VulDB. Administrators using SeaCMS up to 13.6 with the Locoy Collector component are advised to apply patches or mitigations immediately.

Affected products

  • SeaCMS 13.6
  • SeaCMS Locoy Collector

Related CVE's

  • CVE-2026-85137

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities