CVE-2026-85137 | SeaCMS up to 13.6 Locoy Collector seacms_locoy_news.php parseIf pwd code injection

SecurityVulns

A vulnerability was found in SeaCMS up to 13.6. It has been rated as critical. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection.

This vulnerability is listed as CVE-2026-85137. The attack may be initiated remotely. In addition, an exploit is available.VulDB Recent EntriesRead More