CVE-2019-12744: Seeddms

High severity, CVSS 7.5. EPSS: 11.7% chance of exploitation in the next 30 days.

SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.

Affected products

  • Seeddms Seeddms: before 5.1.11 (fixed in 5.1.11)

Published 2019-06-20. Last modified 2026-06-17.