Seacms · Seacms · CVE-2026-82600
**Name of the Vulnerable Software and Affected Versions**
SeaCMS versions prior to 13.7
**Description**
A security flaw allows remote attackers to perform SQL injection, a technique used to interfere with the queries that an application makes to its database. The issue exists in the `/zyapi.php?ac=videolist` endpoint when manipulating the `ids` variable.
**Recommendations**
Update SeaCMS to a version later than 13.6.
As a temporary workaround, restrict access to the `/zyapi.php?ac=videolist` endpoint or avoid using the `ids` variable until the software is updated.