CVE Tools

Lepton-cms

4 CVEs tracked since 2011. Since Sep 2011, none of them reached CISA KEV.

Lepton-cms CVEs per month

Sep 2011 to Feb 2012. Point at a month, or focus the strip and use the arrow keys.
Lepton-cms CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-0910
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-0230

Products

The products that kept showing up in Lepton-cms's monthly top three, with their CVEs summed over those months.

  1. Lepton42 months

Latest CVEs

The 13 most recently published vulnerabilities affecting Lepton-cms.

  1. CVE-2025-56704LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerabilit...8.8
  2. CVE-2024-29514File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.8.8
  3. CVE-2024-29515File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.8.8
  4. CVE-2024-24520An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.7.8
  5. CVE-2024-24399An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.7.2
  6. CVE-2020-24872Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.6.1
  7. CVE-2020-29240Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview sec...4.8
  8. CVE-2020-12705Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.6.1
  9. CVE-2020-12707An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious...6.1
  10. CVE-2012-1000Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to ad...4.3
  11. CVE-2012-0999SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.7.5
  12. CVE-2012-0998Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter.7.5
  13. CVE-2011-3385Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vector...4.3

The record

Peak rank
#27 in Feb 2012
Busiest month shown
Feb 2012, 3 CVEs
Months with a KEV entry
0 since Sep 2011
Monthly snapshots
2 since 2011
Lepton-cms's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store