CVE-2020-28727: Seeddms
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
Affected products
- Seeddms Seeddms: version 6.0.13 only
Published 2020-12-07. Last modified 2026-07-09.