← Back

Seopanel

seopanel

24 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Seo Panel
seo_panel
Seopanel
seopanel

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seopanel
1Seo Panel
Apr 23, 2025
Apr 17, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
1Seopanel
1Seo Panel
Apr 23, 2025
Apr 17, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
1Seopanel
1Seo Panel
Jun 20, 2025
Jan 30, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.
1Seopanel
1Seo Panel
May 29, 2025
Jan 30, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enab...Show more
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.Show less
1Seopanel
1Seo Panel
Jun 4, 2025
Jan 30, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
1Seopanel
1Seo Panel
May 30, 2025
Jan 30, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.
1Seopanel
1Seo Panel
Mar 20, 2025
Feb 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
1Seopanel
1Seo Panel
Nov 21, 2024
Nov 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) rev...Show more
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, (j) webmaster-tools.php, and (k) reports.php; the (3) order_col parameter in (a) analytics.php, (b) review.php, (c) social_media.php, and (d) webmaster-tools.php; and the (4) pageno parameter in (a) alerts.php, (b) log.php, (c) keywords.php, (d) proxy.php, (e) searchengine.php, and (f) siteauditor.php.Show less
1Seopanel
1Seopanel
Nov 21, 2024
Aug 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 25, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 18, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Jan 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
1Seopanel
1Seo Panel
Nov 21, 2024
Dec 31, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.
1Seopanel
1Seo Panel
Nov 21, 2024
Mar 2, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites...Show more
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.Show less
1Seopanel
1Seo Panel
May 13, 2026
Aug 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.