Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Gxlcms

15 known vulnerabilities

7
CRITICAL
6
HIGH
2
MEDIUM

Top Products

gxlcms 9 gxlcms qy 6
15 CVEs
9.8
CVE-2020-20975

In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

9.8
CVE-2018-18488

In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.

7.5
CVE-2018-18487

In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafel

6.1
CVE-2018-16655

Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.

4.9
CVE-2018-16437

Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.

7.2
CVE-2018-16436

Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.

8.8
CVE-2018-15177

In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.

9.8
CVE-2018-14685

The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitr

9.8
CVE-2018-9852

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by

7.5
CVE-2018-9851

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified

7.5
CVE-2018-9850

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directo

9.8
CVE-2018-9848

In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to ex

9.8
CVE-2018-9847

In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execu

9.8
CVE-2018-9247

The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execu

7.5
CVE-2017-14979

Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to

Frequently Asked Questions

How many CVEs affect Gxlcms?

Gxlcms has 15 CVE records in our database, including 7 critical and 6 high severity vulnerabilities.

What are the most severe Gxlcms vulnerabilities?

Gxlcms has 7 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Gxlcms vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gxlcms products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Gxlcms Vulnerabilities

CyberStrike scans your infrastructure for Gxlcms vulnerabilities and provides real-time remediation guidance.

Get Started