CVE-2020-36932: Seacms
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
Affected products
- Seacms Seacms: version 11.1 only
Published 2026-01-25. Last modified 2026-06-17.