{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/seacms--13.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82598"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SeaCMS (\u003c= 13.6)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","rce","webserver","web-application-vulnerability","sql-injection","cve-2026-82600"],"_cs_type":"advisory","_cs_vendors":["SeaCMS"],"content_html":"\u003cp\u003eSeaCMS versions up to 13.6 are vulnerable to a remote code injection vulnerability located within the Template Engine component. The flaw resides in the 'parseIf' function within the 'search.php' file. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request that manipulates the 'searchtype' argument. Successful exploitation allows for the execution of arbitrary code on the underlying web server, potentially leading to full system compromise. This vulnerability has been publicly disclosed and is considered actively exploitable, posing a high risk to organizations utilizing this content management system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-82598 allows an attacker to achieve remote code execution (RCE) on the host web server. This can lead to unauthorized data access, system disruption, modification of web content, or further movement into the internal network. Given the prevalence of CMS vulnerabilities, this flaw is likely to be targeted by automated scanners and automated exploit scripts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate remediation of all SeaCMS installations. If an official patch is available from the vendor, apply it immediately. If no patch is available, ensure the web application is behind a Web Application Firewall (WAF) configured to inspect HTTP parameters for malicious payloads.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all web servers running SeaCMS 13.6 or earlier.\u003c/li\u003e\n\u003cli\u003eConfigure WAF rules to sanitize or block input to the 'searchtype' parameter in 'search.php' that contains suspicious characters or script tags.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting 'search.php' with unusual 'searchtype' parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T03:13:48Z","date_published":"2026-08-31T03:13:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-seacms-code-injection/","summary":"SeaCMS versions 13.6 and earlier contain a code injection vulnerability in the search.php file, allowing remote attackers to execute arbitrary code via the searchtype parameter.","title":"Remote Code Injection in SeaCMS Template Engine","url":"https://feed.craftedsignal.io/briefs/2026-08-seacms-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - SeaCMS (\u003c= 13.6)","version":"https://jsonfeed.org/version/1.1"}