Gdidees develops a content management system that has surfaced vulnerabilities centered on file-upload handling, access controls, and web-application input sanitization. The recurring exposure reflects common weaknesses in web-facing CMS platforms where user-supplied content intersects with file storage and rendering. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gdidees over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27179HIGH GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php. | Apr 11, 2023 | 7.5 | 75 | NO | YES |
CVE-2023-27178CRITICAL An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file. | Apr 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-46101CRITICAL GDidees CMS <= v3.9.1 has a file upload vulnerability. | Sep 20, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-27180HIGH GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php. | Apr 7, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-44758MEDIUM GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title. | Oct 6, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gdidees.
Media articles that mention a CVE ID that affects a product developed by Gdidees — matched by CVE ID, not by vendor name.