← Back

Gilacms

gilacms

25 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Gila Cms
gila_cms

CVEs (25)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gilacms
1Gila Cms
Nov 21, 2024
Oct 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
1Gilacms
1Gila Cms
Nov 21, 2024
Sep 21, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
1Gilacms
1Gila Cms
Nov 21, 2024
Jun 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gila CMS 1.9.1 has XSS.
1Gilacms
1Gila Cms
Nov 21, 2024
Apr 25, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.
1Gilacms
1Gila Cms
Nov 21, 2024
Apr 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.