CVE-2024-54879: Seacms

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

Affected products

  • Seacms Seacms: version 13.1 only

Published 2025-01-06. Last modified 2026-07-05.