VYPR

Gila CMS

by Gila

Source repositories

CVEs (25)

  • CVE-2020-26625LowJan 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.

  • CVE-2020-26624LowJan 2, 2024
    risk 0.25cvss 3.8epss 0.01

    A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.

  • CVE-2020-26623LowJan 2, 2024
    risk 0.25cvss 3.8epss 0.01

    SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.

  • CVE-2024-7657LowAug 12, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site scripting. The attack…

  • CVE-2019-17536MedOct 13, 2019
    risk 0.00cvss 4.9epss 0.02

    Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.

Page 2 of 2