Security Advisory

CVE-2025-22974

9.8
CRITICAL

Vulnerability Description

SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
Published Date February 24, 2025
Official Source NIST NVD Advisory