Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gxlcms gxlcms 2.0 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-18488
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.
Gxlcms Gxlcms 2.0
7.2
CVSSv3
CVE-2018-16436
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
Gxlcms Gxlcms 2.0
8.8
CVSSv3
CVE-2018-15177
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
Gxlcms Gxlcms 2.0
4.9
CVSSv3
CVE-2018-16437
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
Gxlcms Gxlcms 2.0
7.5
CVSSv3
CVE-2018-18487
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.
Gxlcms Gxlcms 2.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-3611
CVE-2024-4947
CVE-2024-32988
CVE-2020-35165
local file inclusion
CVE-2024-4980
bypass
malicious code
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started