Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gxlcms gxlcms 2.0 vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2018-18488
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.
Gxlcms Gxlcms 2.0
578
VMScore
CVE-2018-16436
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
Gxlcms Gxlcms 2.0
605
VMScore
CVE-2018-15177
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
Gxlcms Gxlcms 2.0
356
VMScore
CVE-2018-16437
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
Gxlcms Gxlcms 2.0
445
VMScore
CVE-2018-18487
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.
Gxlcms Gxlcms 2.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started