Lepton-cms
4 CVEs tracked since 2011. Since Sep 2011, none of them reached CISA KEV.
Lepton-cms CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2011-09 | 1 | 0 |
| 2011-10 | null or fewer | |
| 2011-11 | null or fewer | |
| 2011-12 | null or fewer | |
| 2012-01 | null or fewer | |
| 2012-02 | 3 | 0 |
Products
The products that kept showing up in Lepton-cms's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 13 most recently published vulnerabilities affecting Lepton-cms.
- CVE-2025-56704LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerabilit...8.8
- CVE-2024-29514File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.8.8
- CVE-2024-29515File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.8.8
- CVE-2024-24520An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.7.8
- CVE-2024-24399An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.7.2
- CVE-2020-24872Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.6.1
- CVE-2020-29240Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview sec...4.8
- CVE-2020-12705Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.6.1
- CVE-2020-12707An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious...6.1
- CVE-2012-1000Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to ad...4.3
- CVE-2012-0999SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.7.5
- CVE-2012-0998Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter.7.5
- CVE-2011-3385Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vector...4.3
The record
- Peak rank
- #27 in Feb 2012
- Busiest month shown
- Feb 2012, 3 CVEs
- Months with a KEV entry
- 0 since Sep 2011
- Monthly snapshots
- 2 since 2011