Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Simon Njuguna

#20366of 53,635
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-22403
5.4
2025-05-21
Seeddms · Seeddms · CVE-2025-45754
**Name of the Vulnerable Software and Affected Versions** SeedDMS version 6.0.32 **Description** A stored cross-site scripting (XSS) issue exists, allowing an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name. **Recommendations** For SeedDMS version 6.0.32, consider restricting the ability to create documents with arbitrary names to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2025-22419
7.2
2025-05-21
Seeddms · Seeddms · CVE-2025-45752
**Name of the Vulnerable Software and Affected Versions** SeedDMS version 6.0.32 **Description** A vulnerability in SeedDMS allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager. **Recommendations** For SeedDMS version 6.0.32, consider disabling the zip import functionality in the Extension Manager as a temporary workaround until a patch is available. Restrict access to the Extension Manager to minimize the risk of exploitation.