References https://www.fortinet.com/blog/threat-research/multiple-malware-campaigns-target-vmware-vulnerability https://github.com/pysnow1/vul_discovery/blob/main/SeaCMS/SeaCMS%20v12.9%20admin_ping.php%20RCE.md https://www.exploit-db.com/exploits/49249 https://github.com/advisories/GHSA-7cg4-g3qc-hjr8 https://github.com/advisories/GHSA-8gxh-frmx-w55f https://cve.akaoma.com/vendor/seacms https://feedly.com/cve/vendors/seacms https://github.com/202110420106/CVE/blob/master/seacms/seacms_rce.md https://blog.csdn.net/RestoreJustice/article/details/129650247 https://github.com/seacms-com/seacms/issues/21
Related Vulnerabilities(CVE-2025-15002)SeaCMS 13.3版本SQL注入漏洞(CVE-2025-15003)SeaCMS至13.3版本admin_video.php文件SQL注入漏洞seacms-rce: SeaCMS RCEseacms-sqli: SeaCMS sqliseacms-v654-rce: SeaCMS V654 RCEseacmsv645-command-exec: SeaCMS V645 RCEPoCCVE-2011-5107: Alert Before Your Post <= 0.1.1 - Cross-Site ScriptingPoCCVE-2012-4032: WebsitePanel before v1.2.2.1 - Open RedirectPoCCVE-2021-40870: Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command ExecutionPoCCVE-2023-49230: Peplink Balance Two before 8.4.0 - Unauthenticated Config UploadPoCCVE-2018-10738: Nagios XI before 5.4.13 SQL InjectPoCCVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL InjectionPoCCVE-2020-10204: Nexus Repository before 3.21.2 Remote Code Execution