Gilacms develops a focused content-management-system product that, despite a narrow portfolio, occupies a modestly represented niche in the vulnerability landscape. The vendor's disclosure profile centers on a consistent pattern of web-application input-handling and upload-validation weaknesses—including cross-site scripting, SQL injection, cross-site request forgery, path traversal, and unrestricted file uploads—that reflect common risks in CMS platforms where user-supplied content and administrative interfaces converge. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching important for deployments. Defenders should treat Gilacms advisories as a coherent class tied to the platform's web-facing and content-handling attack surface rather than as isolated incidents; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gilacms over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5514CRITICAL Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI. | Jan 6, 2020 | 9.1 | 52 | NO | NO |
CVE-2020-5515HIGH Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. | Jan 6, 2020 | 7.2 | 49 | NO | YES |
CVE-2020-5513MEDIUM Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal. | Jan 6, 2020 | 6.8 | 32 | NO | NO |
CVE-2021-47900CRITICAL Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP h | Jan 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2020-5512MEDIUM Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal. | Jan 6, 2020 | 6.8 | 31 | NO | NO |
CVE-2019-16679MEDIUM Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion. | Sep 21, 2019 | 4.9 | 30 | NO | YES |
CVE-2019-20804HIGH Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account. | May 21, 2020 | 8.8 | 29 | NO | NO |
CVE-2020-20693HIGH A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts. | Sep 27, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-11456HIGH Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code. | Apr 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-9647MEDIUM Gila CMS 1.9.1 has XSS. | Jun 5, 2019 | 6.1 | 25 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gilacms.
Media articles that mention a CVE ID that affects a product developed by Gilacms — matched by CVE ID, not by vendor name.