{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-85138","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-03T09:10:59.425Z","datePublished":"2026-09-03T15:45:07.568Z","dateUpdated":"2026-09-03T15:55:51.810Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-03T15:45:07.568Z"},"title":"SeaCMS WeChat index.php addslashes sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"SQL Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-74","lang":"en","description":"Injection"}]}],"affected":[{"vendor":"n/a","product":"SeaCMS","versions":[{"version":"13.0","status":"affected"},{"version":"13.1","status":"affected"},{"version":"13.2","status":"affected"},{"version":"13.3","status":"affected"},{"version":"13.4","status":"affected"},{"version":"13.5","status":"affected"},{"version":"13.6","status":"affected"}],"cpes":["cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*"],"modules":["WeChat Module"]}],"descriptions":[{"lang":"en","value":"A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public and may be used."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-03T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-03T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-03T11:16:21.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"T-Chachamaru (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/398365","name":"VDB-398365 | SeaCMS WeChat index.php addslashes sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/398365/cti","name":"VDB-398365 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-85138","name":"CVE-2026-85138 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/892793","name":"Submit #892793 | SeaCMS 13.6 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/T-Chachamaru/seacms-13.6-security-advisories/blob/a084a3e573240d54860153321df271280daec262/d-003-weixin-xml-entity-sqli.md","tags":["exploit"]}],"tags":["x_freeware"],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-03T15:54:59.850482Z","id":"CVE-2026-85138","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-03T15:55:51.810Z"}}]}}