CVE-2020-26623: Gilacms Gila CMS

Low severity, CVSS 3.8. EPSS: 0.7% chance of exploitation in the next 30 days.

SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.

Affected products

  • Gilacms Gila CMS: up to and including 1.15.4

Published 2024-01-02. Last modified 2026-07-09.