Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
14042.1%MEDIUM

Related CVEs

4
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-7657A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.MEDIUM5.342.1%Aug 12, 2024
CVE-2020-26625A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.LOW3.8Jan 2, 2024
CVE-2020-26624A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.LOW3.8Jan 2, 2024
CVE-2020-26623SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.LOW3.8Jan 2, 2024