Gxlcms is a content-management system with a modestly distributed footprint whose vulnerabilities skew strongly toward critical severity outcomes. The exposure concentrates in the core product and its variants and recurs through application-layer weaknesses including SQL injection, sensitive-information disclosure, path traversal, code injection, and cross-site request forgery—a pattern characteristic of web-facing CMS platforms with input-handling and access-control demands. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gxlcms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9848CRITICAL In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Confi | Apr 7, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-20975CRITICAL In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. | Aug 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-18488CRITICAL In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. | Oct 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-9852CRITICAL In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a query string within a Home-Hit | Apr 8, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14685CRITICAL The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request | Jul 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-9847CRITICAL In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template. | Apr 7, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-9247CRITICAL The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequen | Apr 4, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-15177HIGH In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. | Aug 8, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-9851HIGH In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of | Apr 8, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-9850HIGH In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data- | Apr 8, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gxlcms.
Media articles that mention a CVE ID that affects a product developed by Gxlcms — matched by CVE ID, not by vendor name.