CVE-2020-26625: Gilacms Gila CMS
Low severity, CVSS 3.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
Affected products
- Gilacms Gila CMS: up to and including 1.15.4
Published 2024-01-02. Last modified 2026-07-09.