Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-7657 A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2… Gila Cms Mitigation only Fix from $1,6002024-08-12 MEDIUM 6.1 CVE-2020-20523 Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during t… Gila Cms No fix yet Fix from $1,6002023-08-11 HIGH 8.8 CVE-2020-20726 Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user para… Gila Cms No fix yet Fix from $1,9502023-06-20 HIGH 7.5 CVE-2021-37777 Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just… Gila Cms No fix yet Fix from $1,9502021-10-04 MEDIUM 5.4 CVE-2021-39486 A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary cod… Gila Cms No fix yet Fix from $1,6002021-10-04 HIGH 8.8 CVE-2020-20693 A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts. Gila Cms No fix yet Fix from $1,9502021-09-27 HIGH 7.2 CVE-2020-20692 GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php. Gila Cms No fix yet Fix from $1,9502021-09-27 MEDIUM 5.4 CVE-2020-20695 A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file. Gila Cms No fix yet Fix from $1,6002021-09-27 MEDIUM 5.4 CVE-2020-20696 A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a … Gila Cms No fix yet Fix from $1,6002021-09-27 HIGH 7.2 CVE-2020-28692 In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files. Gila Cms No fix yet Fix from $1,9502020-11-16 HIGH 8.8 CVE-2019-20804 Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account. Gila Cms 1.11.6+ Fix from $1,9502020-05-21 MEDIUM 6.1 CVE-2019-20803 Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme. Gila Cms 1.11.6+ Fix from $1,6002020-05-21 MEDIUM 6.8 CVE-2020-5512EPSS 19% Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal. Gila Cms No fix yet Fix from $1,6002020-01-06 MEDIUM 6.8 CVE-2020-5513EPSS 26% Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal. Gila Cms No fix yet Fix from $1,6002020-01-06 CRITICAL 9.1 CVE-2020-5514EPSS 44% Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI. Gila Cms No fix yet Fix from $2,3002020-01-06 HIGH 7.2 CVE-2020-5515EPSS 27% Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. Gila Cms No fix yet Fix from $1,9502020-01-06 MEDIUM 6.1 CVE-2019-17535 Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-96… Gila Cms after 1.11.4 Fix from $1,6002019-10-13 MEDIUM 6.1 CVE-2019-9647 Gila CMS 1.9.1 has XSS. Gila Cms No fix yet Fix from $1,6002019-06-05 HIGH 8.8 CVE-2019-11456 Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code. Gila Cms No fix yet Fix from $1,9502019-04-22