CVE-2020-23048: Seeddms

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

Affected products

  • Seeddms Seeddms: version 4.3.37 only; version 5.0.13 only; version 5.1.14 only; version 5.1.16 only; version 5.1.18 only; version 6.0.7 only

Published 2021-10-22. Last modified 2026-06-17.