CVE-2020-20692: Gilacms Gila CMS

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.

Affected products

  • Gilacms Gila CMS: version 1.11.4 only

Published 2021-09-27. Last modified 2026-06-17.