SeaCMS 11.1 contains a stored cross-site scripting...
Moderate severity
Unreviewed
Published
Jan 25, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jan 25, 2026
Published to the GitHub Advisory Database
Jan 25, 2026
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
References