CVE-2026-82598

A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 01:16

Updated : 2026-09-01 15:17


NVD link : CVE-2026-82598

Mitre link : CVE-2026-82598

CVE.ORG link : CVE-2026-82598


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')