---
cve: "CVE-2026-82601"
severity: "MEDIUM"
cvss: 5.3
epss: "3.8%"
vendor: "n/a"
kev: false
exploited: false
published: "2026-08-31 02:17:02"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T08:40:10+02:00"
---

# CVE-2026-82601

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Referenzen

- <https://vuldb.com/vuln/397103>
- <https://vuldb.com/vuln/397103/cti>
- <https://vuldb.com/cve/CVE-2026-82601>
- <https://vuldb.com/submit/892786>
- <https://github.com/T-Chachamaru/seacms-13.6-security-advisories/blob/a084a3e573240d54860153321df271280daec262/c-007-errtxt-reflected-xss.md>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-82601) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
