Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gila Cms MEDIUM 5.4
CVE-2024-7657

A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2…

Mitigation only
Fix from $1,600 2024-08-12
Gila Cms MEDIUM 6.1
CVE-2020-20523

Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during t…

No fix yet
Fix from $1,600 2023-08-11
Gila Cms HIGH 8.8
CVE-2020-20726

Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user para…

No fix yet
Fix from $1,950 2023-06-20
Gila Cms HIGH 7.5
CVE-2021-37777

Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just…

No fix yet
Fix from $1,950 2021-10-04
Gila Cms MEDIUM 5.4
CVE-2021-39486

A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary cod…

No fix yet
Fix from $1,600 2021-10-04
Gila Cms HIGH 8.8
CVE-2020-20693

A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.

No fix yet
Fix from $1,950 2021-09-27
Gila Cms HIGH 7.2
CVE-2020-20692

GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.

No fix yet
Fix from $1,950 2021-09-27
Gila Cms MEDIUM 5.4
CVE-2020-20695

A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.

No fix yet
Fix from $1,600 2021-09-27
Gila Cms MEDIUM 5.4
CVE-2020-20696

A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a …

No fix yet
Fix from $1,600 2021-09-27
Gila Cms HIGH 7.2
CVE-2020-28692

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

No fix yet
Fix from $1,950 2020-11-16
Gila Cms HIGH 8.8
CVE-2019-20804

Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.

Fix: 1.11.6+
Fix from $1,950 2020-05-21
Gila Cms MEDIUM 6.1
CVE-2019-20803

Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme.

Fix: 1.11.6+
Fix from $1,600 2020-05-21
Gila Cms MEDIUM 6.8
CVE-2020-5512EPSS 19%

Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.

No fix yet
Fix from $1,600 2020-01-06
Gila Cms MEDIUM 6.8
CVE-2020-5513EPSS 26%

Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

No fix yet
Fix from $1,600 2020-01-06
Gila Cms CRITICAL 9.1
CVE-2020-5514EPSS 44%

Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

No fix yet
Fix from $2,300 2020-01-06
Gila Cms HIGH 7.2
CVE-2020-5515EPSS 27%

Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.

No fix yet
Fix from $1,950 2020-01-06
Gila Cms MEDIUM 6.1
CVE-2019-17535

Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-96…

Fix: after 1.11.4
Fix from $1,600 2019-10-13
Gila Cms MEDIUM 6.1
CVE-2019-9647

Gila CMS 1.9.1 has XSS.

No fix yet
Fix from $1,600 2019-06-05
Gila Cms HIGH 8.8
CVE-2019-11456

Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.

No fix yet
Fix from $1,950 2019-04-22