CVE-2020-18078: Sem-CMS Semcms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

Affected products

Published 2021-12-17. Last modified 2026-06-17.