Showing 1 vulnerability on this page for Gila CMS

Signals CISA KEV Ransomware Nuclei
Gila CMS vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Gila CMS < 2.0.0 - Remote Code Execution

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

CWE-98Jan 27, 2026
CVSS9.3v4.0EPSS0.602%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX