Skip to main content

Vendor/product archive

seopanel / seo_panel CVEs

Beta · best-effort

22 CVEs tagged to seopanel / seo_panel0 Critical, 5 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2025-29452

Published Apr 17, 2025

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-29451

Published Apr 17, 2025

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-22648

Published Jan 30, 2024

A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local enviro…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22647

Published Jan 30, 2024

An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to dete…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22646

Published Jan 30, 2024

An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22643

Published Jan 30, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34117

Published Feb 15, 2023

SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39413

Published Nov 5, 2021

Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29010

Published Mar 25, 2021

A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29009

Published Mar 25, 2021

A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29008

Published Mar 25, 2021

A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28420

Published Mar 18, 2021

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28419

Published Mar 18, 2021

The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28418

Published Mar 18, 2021

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28417

Published Mar 18, 2021

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3002

Published Jan 1, 2021

Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35930

Published Dec 31, 2020

Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14384

Published Mar 2, 2020

The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10839

Published Aug 29, 2017

SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10838

Published Aug 29, 2017

Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100024

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1855

Published May 20, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel before 3.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) capcheck parameter to direc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1