Known Vulnerabilities for products from Gxlcms

Listed below are 15 of the newest known vulnerabilities associated with the vendor "Gxlcms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-20975 json In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. 9.8 - CRITICAL 2021-08-12 2021-08-20
CVE-2018-18488 json In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. 9.8 - CRITICAL 2018-10-18 2018-11-30
CVE-2018-18487 json In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, re... 7.5 - HIGH 2018-10-18 2018-11-30
CVE-2018-16655 json Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. 6.1 - MEDIUM 2018-09-07 2018-11-09
CVE-2018-16437 json Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. 4.9 - MEDIUM 2018-09-05 2018-11-05
CVE-2018-16436 json Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. 7.2 - HIGH 2018-09-05 2018-11-05
CVE-2018-15177 json In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. 8.8 - HIGH 2018-08-08 2018-10-05
CVE-2018-14685 json The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary f... 9.8 - CRITICAL 2018-07-28 2018-09-28
CVE-2018-9852 json In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embe... 9.8 - CRITICAL 2018-04-08 2020-01-30
CVE-2018-9851 json In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified path... 7.5 - HIGH 2018-04-08 2018-05-17
CVE-2018-9850 json In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory tr... 7.5 - HIGH 2018-04-08 2018-05-14
CVE-2018-9848 json In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute... 9.8 - CRITICAL 2018-04-07 2018-05-14
CVE-2018-9847 json In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute ar... 9.8 - CRITICAL 2018-04-07 2018-05-14
CVE-2018-9247 json The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute ar... 9.8 - CRITICAL 2018-04-04 2018-05-09
CVE-2017-14979 json Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read ... 7.5 - HIGH 2017-10-03 2019-10-03

Known software with vulnerabilities from Gxlcms

Type Vendor Product Version
ApplicationGxlcmsGxlcms-
ApplicationGxlcmsGxlcms Qy1.0.0713

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report