PatchSiren

SeaCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW SeaCMS CVE published 2026-08-31

CVE-2026-82599

A path traversal vulnerability exists in SeaCMS up to version 13.6, specifically in the /member.php?action=chgpwdsubmit file's unlink function. The vulnerability is triggered by manipulating the 'oldpic' argument. This issue allows remote attackers to exploit the system, and a public exploit is available. The CVE record was published on 2026-08-31T01:16:50.630Z and has not been modified since then. The vu [truncated]

MEDIUM SeaCMS CVE published 2026-08-31

CVE-2026-82598

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T01:16:50.417Z and has not been modified since then. A vulnerability was determined in SeaCMS up to 13.6, affecting the parseIf function in search.php of the template engine. Manipulation of the searchtype argument may cause code injection, allowing remote attacks. SeaCMS users and administrators, [truncated]