← Back

Semcms

semcms

Vendor: Sem Cms • 59 CVEs

CVEs (59)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sem Cms
1Semcms
Apr 4, 2025
Apr 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
1Sem Cms
1Semcms
Apr 4, 2025
Apr 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
1Sem Cms
1Semcms
Apr 4, 2025
Apr 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
1Sem Cms
1Semcms
Apr 4, 2025
Mar 29, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain a...Show more
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.Show less
1Sem Cms
1Semcms
Mar 29, 2025
Feb 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
1Sem Cms
1Semcms
Jun 20, 2025
Jan 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
1Sem Cms
1Semcms
Nov 21, 2024
Dec 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
1Sem Cms
1Semcms
Jun 3, 2025
Dec 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engi...Show more
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.Show less
1Sem Cms
1Semcms
Nov 21, 2024
Aug 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
1Sem Cms
1Semcms
Nov 21, 2024
Jul 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
1Sem Cms
1Semcms
Nov 21, 2024
Jun 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
1Sem Cms
1Semcms
Jan 21, 2025
May 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
1Sem Cms
1Semcms
Jan 29, 2025
May 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
1Sem Cms
1Semcms
May 7, 2025
Oct 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
1Sem Cms
1Semcms
May 8, 2025
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.