Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-7657
A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2…
Gila Cms
Mitigation only
MEDIUM 6.1
CVE-2020-20523
Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during t…
Gila Cms
No fix yet
HIGH 8.8
CVE-2020-20726
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user para…
Gila Cms
No fix yet
HIGH 7.5
CVE-2021-37777
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just…
Gila Cms
No fix yet
MEDIUM 5.4
CVE-2021-39486
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary cod…
Gila Cms
No fix yet
HIGH 8.8
CVE-2020-20693
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Gila Cms
No fix yet
HIGH 7.2
CVE-2020-20692
GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.
Gila Cms
No fix yet
MEDIUM 5.4
CVE-2020-20695
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
Gila Cms
No fix yet
MEDIUM 5.4
CVE-2020-20696
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a …
Gila Cms
No fix yet
HIGH 7.2
CVE-2020-28692
In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.
Gila Cms
No fix yet
HIGH 8.8
CVE-2019-20804
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
Gila Cms
1.11.6+
MEDIUM 6.1
CVE-2019-20803
Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme.
Gila Cms
1.11.6+
MEDIUM 6.8
CVE-2020-5512EPSS 19%
Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
Gila Cms
No fix yet
MEDIUM 6.8
CVE-2020-5513EPSS 26%
Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
Gila Cms
No fix yet
CRITICAL 9.1
CVE-2020-5514EPSS 44%
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
Gila Cms
No fix yet
HIGH 7.2
CVE-2020-5515EPSS 27%
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
Gila Cms
No fix yet
MEDIUM 6.1
CVE-2019-17535
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-96…
Gila Cms
after 1.11.4
MEDIUM 6.1
CVE-2019-9647
Gila CMS 1.9.1 has XSS.
Gila Cms
No fix yet
HIGH 8.8
CVE-2019-11456
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
Gila Cms
No fix yet