Gilacms

Gila Cms

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 27.01.2026 15:23:51
  • Zuletzt bearbeitet 29.01.2026 16:31:35

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with sh...

  • EPSS 0.3%
  • Veröffentlicht 12.08.2024 13:38:49
  • Zuletzt bearbeitet 15.08.2024 17:48:20

A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 02.01.2024 22:15:07
  • Zuletzt bearbeitet 16.05.2025 18:16:00

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 02.01.2024 22:15:07
  • Zuletzt bearbeitet 17.06.2025 15:15:34

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 02.01.2024 22:15:07
  • Zuletzt bearbeitet 03.06.2025 15:15:23

SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 11.08.2023 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:12:07

Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during the Gila CMS installation.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 20.06.2023 15:15:10
  • Zuletzt bearbeitet 11.12.2024 15:15:06

Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.10.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:19:32

A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 04.10.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:15:53

Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information di...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 27.09.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:13

GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.