Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gilacms

First CVE: Apr 22, 2019Active for: 7 yearsTotal CVEs: 26
46.5
VTI Score
High

Gilacms develops a focused content-management-system product that, despite a narrow portfolio, occupies a modestly represented niche in the vulnerability landscape. The vendor's disclosure profile centers on a consistent pattern of web-application input-handling and upload-validation weaknesses—including cross-site scripting, SQL injection, cross-site request forgery, path traversal, and unrestricted file uploads—that reflect common risks in CMS platforms where user-supplied content and administrative interfaces converge. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching important for deployments. Defenders should treat Gilacms advisories as a coherent class tied to the platform's web-facing and content-handling attack surface rather than as isolated incidents; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gilacms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
Jan 27, 2026
178 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-5514CRITICAL
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
Jan 6, 20209.152NONO
CVE-2020-5515HIGH
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
Jan 6, 20207.249NOYES
CVE-2020-5513MEDIUM
Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
Jan 6, 20206.832NONO
CVE-2021-47900CRITICAL
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP h
Jan 27, 20269.831NONO
CVE-2020-5512MEDIUM
Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
Jan 6, 20206.831NONO
CVE-2019-16679MEDIUM
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
Sep 21, 20194.930NOYES
CVE-2019-20804HIGH
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
May 21, 20208.829NONO
CVE-2020-20693HIGH
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Sep 27, 20218.827NONO
CVE-2019-11456HIGH
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
Apr 22, 20198.827NONO
CVE-2019-9647MEDIUM
Gila CMS 1.9.1 has XSS.
Jun 5, 20196.125NOYES
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
50%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (53.8%)
Unknown0 (0.0%)
Required12 (46.2%)
Privileges Required
Low4 (15.4%)
High12 (46.2%)
None10 (38.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
11.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gilacms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gilacms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gilacms's Products

View all 3 CNAs →

Top CWEs