A path traversal vulnerability exists in SeaCMS up to version 13.6, specifically in the /member.php?action=chgpwdsubmit file's unlink function. The vulnerability is triggered by manipulating the 'oldpic' argument. This issue allows remote attackers to exploit the system, and a public exploit is available. The CVE record was published on 2026-08-31T01:16:50.630Z and has not been modified since then. The vu [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T01:16:50.417Z and has not been modified since then. A vulnerability was determined in SeaCMS up to 13.6, affecting the parseIf function in search.php of the template engine. Manipulation of the searchtype argument may cause code injection, allowing remote attacks. SeaCMS users and administrators, [truncated]