Gila Cms

Vendor:

First CVE: Apr 22, 2019 · Active for 7 years

26
Total CVEs
More Total CVEs than 96% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gila Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
Jan 27, 2026
182 days ago

CVE Severity & Scoring

Gila Cms26 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (53.8%)
Unknown0 (0.0%)
Required12 (46.2%)
Privileges Required
Low4 (15.4%)
High12 (46.2%)
None10 (38.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
Jan 6, 20209.152NONO
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
Jan 6, 20207.249NOYES
Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.
Jan 6, 20206.832NONO
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP h
Jan 27, 20269.831NONO
Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.
Jan 6, 20206.831NONO
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
Sep 21, 20194.930NOYES
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
May 21, 20208.829NONO
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Sep 27, 20218.827NONO
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
Apr 22, 20198.827NONO
Gila CMS 1.9.1 has XSS.
Jun 5, 20196.125NOYES

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
11.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Gila Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2.026.51.1%00
1.9.116.12.3%01
1.16.017.21.6%00
1.11.847.528.8%01
1.11.457.10.7%00
1.11.316.10.6%00
1.10.915.40.6%00
1.10.126.81.5%00