Record summary

CVE-2020-36932 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 26, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 11.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBSeacms 11.1 - 'checkuser' Stored XSSExploitDB exploitby j5sNot analyzed1 file
ExploitDB

PoC details

References

4