CVE-2026-82600

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
31/08/2026
Last modified:
31/08/2026

Description

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.