{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-82598","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-08-30T06:42:03.070Z","datePublished":"2026-08-31T00:30:07.314Z","dateUpdated":"2026-09-01T14:46:26.611Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-08-31T00:30:07.314Z"},"title":"SeaCMS Template search.php parseIf code injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-74","lang":"en","description":"Injection"}]}],"affected":[{"vendor":"n/a","product":"SeaCMS","versions":[{"version":"13.0","status":"affected"},{"version":"13.1","status":"affected"},{"version":"13.2","status":"affected"},{"version":"13.3","status":"affected"},{"version":"13.4","status":"affected"},{"version":"13.5","status":"affected"},{"version":"13.6","status":"affected"}],"cpes":["cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*"],"modules":["Template Engine"]}],"descriptions":[{"lang":"en","value":"A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-08-30T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-08-30T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-08-30T08:47:10.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"T-Chachamaru (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/397100","name":"VDB-397100 | SeaCMS Template search.php parseIf code injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/397100/cti","name":"VDB-397100 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-82598","name":"CVE-2026-82598 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/892763","name":"Submit #892763 | SeaCMS 13.6 Code Injection","tags":["third-party-advisory"]},{"url":"https://github.com/T-Chachamaru/seacms-13.6-security-advisories/blob/a084a3e573240d54860153321df271280daec262/c-009-search-cascade-template-rce.md","tags":["exploit"]}],"tags":["x_freeware"],"x_generator":["VulDB PVTS v202608"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-01T14:46:16.639002Z","id":"CVE-2026-82598","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-01T14:46:26.611Z"}}]}}