CVE-2024-54880: Seacms
Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Affected products
- Seacms Seacms: version 13.1 only
Published 2025-01-06. Last modified 2026-06-17.