An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.
https://github.com/seacmscom/seacms
https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-79423.md