Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Seeddms

First CVE: Mar 20, 2014Active for: 12 yearsTotal CVEs: 33
27.3
VTI Score
Low

Seeddms is a document management system with a focused vulnerability footprint concentrated in a single widely deployed product. The recurring exposure pattern centers on web-application layer weaknesses—cross-site scripting, cross-site request forgery, path traversal, open redirect, and improper input validation—that reflect the common input-handling and navigation challenges faced by browser-based document platforms. The vendor's disclosures have a moderate tendency toward public exploit availability, making disclosed flaws a practical attack vector once identified. Defenders should prioritize input-validation and access-control hardening in deployed instances and remain attentive to the web-tier attack surface this product presents. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Seeddms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2014
12 years ago
Most Recent CVE
May 21, 2025
429 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12744HIGH
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
Jun 20, 20197.540NOYES
CVE-2022-44938CRITICAL
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
Dec 8, 20229.830NONO
CVE-2019-12801MEDIUM
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
Jun 17, 20196.130NOYES
CVE-2019-12745MEDIUM
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
Jun 20, 20195.429NOYES
CVE-2018-12940HIGH
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploadi
Jul 31, 20188.828NONO
CVE-2018-12941HIGH
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" pa
Jul 31, 20188.827NONO
CVE-2018-12942HIGH
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query w
Jul 31, 20188.826NONO
CVE-2021-33223HIGH
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
Jun 7, 20238.825NONO
CVE-2022-28478MEDIUM
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attack
Jun 6, 20226.522NONO
CVE-2021-45408MEDIUM
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
Feb 4, 20226.121NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
79%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (90.9%)
Unknown3 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (87.9%)
High1 (3.0%)
Unknown3 (9.1%)
User Interaction
None9 (27.3%)
Unknown3 (9.1%)
Required21 (63.6%)
Privileges Required
Low11 (33.3%)
High3 (9.1%)
None16 (48.5%)
Unknown3 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Seeddms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Seeddms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Seeddms's Products

View all 1 CNAs →

Top CWEs