lepton-cms records
13 published records for vendor lepton-cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-29514No exploit | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | High8.8 | — | 1.3% | Apr 2, 2024 |
35Monitor | CVE-2024-29515No exploit | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | High8.8 | — | 1.2% | Mar 25, 2024 |
35Monitor | CVE-2025-56704No exploit | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded fileslepton-cms · leptoncms · CWE-434 | High8.8 | — | 0.8% | Dec 9, 2025 |
33Monitor | CVE-2024-24399No exploit | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code lepton-cms · leptoncms · CWE-434 | High7.2 | — | 15.6% | Jan 25, 2024 |
31Monitor | CVE-2012-0998No exploit | Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrarylepton-cms · lepton · CWE-22 | High7.5 | — | 1.9% | Feb 24, 2012 |
31Monitor | CVE-2024-24520No exploit | An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.lepton-cms · leptoncms · CWE-94 | High7.8 | — | 0.4% | Mar 20, 2024 |
30Monitor | CVE-2012-0999No exploit | SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via thelepton-cms · lepton · CWE-89 | High7.5 | — | 1.3% | Feb 24, 2012 |
24Monitor | CVE-2020-12707Proof of concept | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.lepton-cms · lepton cms · CWE-79 | Medium6.1 | — | 1.2% | May 7, 2020 |
24Monitor | CVE-2020-12705No exploit | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.lepton-cms · leptoncms · CWE-79 | Medium6.1 | — | 0.6% | May 7, 2020 |
24Monitor | CVE-2020-24872No exploit | Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitralepton-cms · leptoncms · CWE-79 | Medium6.1 | — | 0.5% | Aug 11, 2023 |
20Monitor | CVE-2020-29240Proof of concept | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).lepton-cms · leptoncms · CWE-79 | Medium4.8 | — | 1.7% | Dec 2, 2020 |
17Monitor | CVE-2012-1000No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitralepton-cms · lepton · CWE-79 | Medium4.3 | — | 1.2% | Feb 24, 2012 |
17Monitor | CVE-2011-3385No exploit | Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers lepton-cms · lepton · CWE-79 | Medium4.3 | — | 0.8% | Sep 2, 2011 |
- CVE-2024-2951435Monitor
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
HighCVSS 8.8No exploitEPSS 1%lepton-cms · leptoncmsApr 2, 2024
- CVE-2024-2951535Monitor
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
HighCVSS 8.8No exploitEPSS 1%lepton-cms · leptoncmsMar 25, 2024
- CVE-2025-5670435Monitor
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files
HighCVSS 8.8No exploitEPSS 1%lepton-cms · leptoncmsDec 9, 2025
- CVE-2024-2439933Monitor
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code
HighCVSS 7.2No exploitEPSS 16%lepton-cms · leptoncmsJan 25, 2024
- CVE-2012-099831Monitor
Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary
HighCVSS 7.5No exploitEPSS 2%lepton-cms · leptonFeb 24, 2012
- CVE-2024-2452031Monitor
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
HighCVSS 7.8No exploitEPSS 0%lepton-cms · leptoncmsMar 20, 2024
- CVE-2012-099930Monitor
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5No exploitEPSS 1%lepton-cms · leptonFeb 24, 2012
- CVE-2020-1270724Monitor
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.
MediumCVSS 6.1Proof of conceptEPSS 1%lepton-cms · lepton cmsMay 7, 2020
- CVE-2020-1270524Monitor
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
MediumCVSS 6.1No exploitEPSS 1%lepton-cms · leptoncmsMay 7, 2020
- CVE-2020-2487224Monitor
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitra
MediumCVSS 6.1No exploitEPSS 1%lepton-cms · leptoncmsAug 11, 2023
- CVE-2020-2924020Monitor
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).
MediumCVSS 4.8Proof of conceptEPSS 2%lepton-cms · leptoncmsDec 2, 2020
- CVE-2012-100017Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitra
MediumCVSS 4.3No exploitEPSS 1%lepton-cms · leptonFeb 24, 2012
- CVE-2011-338517Monitor
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers
MediumCVSS 4.3No exploitEPSS 1%lepton-cms · leptonSep 2, 2011