CVE-2026-85137

A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 16:18

Updated : 2026-09-05 02:17


NVD link : CVE-2026-85137

Mitre link : CVE-2026-85137

CVE.ORG link : CVE-2026-85137


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')