References https://cyc1e183.github.io/2018/12/20/Seacms-6-54-6-55-%E4%BB%BB%E6%84%8F%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/ https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Seacms/Seacms%20V6.54%20%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/tr1ple/p/11100975.html https://cn-sec.com/archives/2298124.html https://foxgrin.github.io/posts/10257/ https://security.zone.ci/aliyun/ali_nonvd/243600.html https://github.com/SecWiki/CMS-Hunter/blob/master/seacms/seacms6.54%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C/seacms6.54.md https://cloud.tencent.com/developer/news/10441 https://www.cnblogs.com/zhaijiahui/p/7648350.html https://github.com/jiangsir404/PHP-code-audit/blob/master/seacms/seacms%20%E5%A4%9A%E4%B8%AA%E7%89%88%E6%9C%AC%E7%9A%84%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%E6%80%BB%E7%BB%93(search.php).md
Related VulnerabilitiesPoCCVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL InjectionCloudreve网盘 /api/v3/share/search 未授权访问漏洞Piwigo /ws.php pwg.history.search 未授权访问漏洞(CVE-2026-27833)WordPress WP-Advanced-Search /autocompletion-PHP5.5.php SQL 注入漏洞(CVE-2024-9796)MLflow /ajax-api/3.0/jobs/search 权限绕过漏洞 (CVE-2026-2652)深信服运维安全管理系统 /fort/login/search_login 信息泄露漏洞SillyTavern /api/search/searxng 服务器端请求伪造漏洞(CVE-2026-46372)用友KSOA search_list.jsp 存在sql注入漏洞PoCCVE-2026-42031: CKAN DataStore SQL Search - SQL InjectionCKAN /api/action/datastore_search_sql SQL 注入漏洞(CVE-2026-42031)用友NC Cloud /ncchr/pm/ref/indiIssued/blobRefClassSearch 代码执行漏洞PoCCVE-2025-71258: BMC FootPrints 'searchWeb' - Server-Side Request Forgery东胜物流软件 HtmlSearchServiceLCL.aspx 存在SQL注入漏洞