Skip to content
Noroxi

lepton-cms records

13 published records for vendor lepton-cms.

All records

13 records
  • File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi

    HighCVSS 8.8No exploitEPSS 1%

    lepton-cms · leptoncmsApr 2, 2024

  • File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi

    HighCVSS 8.8No exploitEPSS 1%

    lepton-cms · leptoncmsMar 25, 2024

  • LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files

    HighCVSS 8.8No exploitEPSS 1%

    lepton-cms · leptoncmsDec 9, 2025

  • An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code

    HighCVSS 7.2No exploitEPSS 16%

    lepton-cms · leptoncmsJan 25, 2024

  • CVE-2012-0998
    31Monitor

    Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary

    HighCVSS 7.5No exploitEPSS 2%

    lepton-cms · leptonFeb 24, 2012

  • An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

    HighCVSS 7.8No exploitEPSS 0%

    lepton-cms · leptoncmsMar 20, 2024

  • CVE-2012-0999
    30Monitor

    SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5No exploitEPSS 1%

    lepton-cms · leptonFeb 24, 2012

  • An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    lepton-cms · lepton cmsMay 7, 2020

  • Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.

    MediumCVSS 6.1No exploitEPSS 1%

    lepton-cms · leptoncmsMay 7, 2020

  • Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitra

    MediumCVSS 6.1No exploitEPSS 1%

    lepton-cms · leptoncmsAug 11, 2023

  • Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).

    MediumCVSS 4.8Proof of conceptEPSS 2%

    lepton-cms · leptoncmsDec 2, 2020

  • CVE-2012-1000
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitra

    MediumCVSS 4.3No exploitEPSS 1%

    lepton-cms · leptonFeb 24, 2012

  • CVE-2011-3385
    17Monitor

    Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers

    MediumCVSS 4.3No exploitEPSS 1%

    lepton-cms · leptonSep 2, 2011