CVE-2018-19349: Seacms

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

Affected products

  • Seacms Seacms: version 6.64 only

Published 2018-11-17. Last modified 2026-06-17.