Seeddms is a document management system with a focused vulnerability footprint concentrated in a single widely deployed product. The recurring exposure pattern centers on web-application layer weaknesses—cross-site scripting, cross-site request forgery, path traversal, open redirect, and improper input validation—that reflect the common input-handling and navigation challenges faced by browser-based document platforms. The vendor's disclosures have a moderate tendency toward public exploit availability, making disclosed flaws a practical attack vector once identified. Defenders should prioritize input-validation and access-control hardening in deployed instances and remain attentive to the web-tier attack surface this product presents. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seeddms over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12744HIGH SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940. | Jun 20, 2019 | 7.5 | 40 | NO | YES |
CVE-2022-44938CRITICAL Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack. | Dec 8, 2022 | 9.8 | 30 | NO | NO |
CVE-2019-12801MEDIUM out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. | Jun 17, 2019 | 6.1 | 30 | NO | YES |
CVE-2019-12745MEDIUM out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. | Jun 20, 2019 | 5.4 | 29 | NO | YES |
CVE-2018-12940HIGH Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploadi | Jul 31, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-12941HIGH This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" pa | Jul 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12942HIGH SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query w | Jul 31, 2018 | 8.8 | 26 | NO | NO |
CVE-2021-33223HIGH An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file. | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-28478MEDIUM SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attack | Jun 6, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-45408MEDIUM Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter. | Feb 4, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seeddms.
Media articles that mention a CVE ID that affects a product developed by Seeddms — matched by CVE ID, not by vendor name.