Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    7
    Critical Level Threats
    6
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-20975

    In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

    Last Modified: Nov 21, 2024
    Published: Aug 12, 2021

    CVE-2018-18488

    In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.

    Last Modified: Nov 21, 2024
    Published: Oct 18, 2018

    CVE-2018-18487

    In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.

    Last Modified: Nov 21, 2024
    Published: Oct 18, 2018

    CVE-2018-16655

    Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.

    Last Modified: Nov 21, 2024
    Published: Sep 07, 2018

    CVE-2018-16436

    Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.

    Last Modified: Nov 21, 2024
    Published: Sep 05, 2018
    Items Per Page
    Gxlcms Vulnerabilities & Security CVEs | CVE-DB