lightcms project records
6 published records for vendor lightcms project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-27112No exploit | LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading olightcms project · lightcms | Critical9.8 | — | 2.4% | Apr 15, 2021 |
39Monitor | CVE-2023-27060No exploit | LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.lightcms project · lightcms · CWE-306 | Critical9.8 | — | 1.3% | Mar 22, 2023 |
24Monitor | CVE-2026-29934No exploit | A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Jalightcms project · lightcms · CWE-79 | Medium6.1 | — | 0.3% | Mar 26, 2026 |
23Monitor | CVE-2021-3355Proof of concept | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/Slightcms project · lightcms · CWE-79 | Medium5.4 | — | 7.3% | Feb 24, 2021 |
21Monitor | CVE-2024-22559No exploit | LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.lightcms project · lightcms · CWE-79 | Medium5.4 | — | 0.3% | Jan 29, 2024 |
19Monitor | CVE-2022-33009No exploit | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploadinlightcms project · lightcms · CWE-79 | Medium4.8 | — | 0.5% | Jun 27, 2022 |
- CVE-2021-2711240Plan
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading o
CriticalCVSS 9.8No exploitEPSS 2%lightcms project · lightcmsApr 15, 2021
- CVE-2023-2706039Monitor
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
CriticalCVSS 9.8No exploitEPSS 1%lightcms project · lightcmsMar 22, 2023
- CVE-2026-2993424Monitor
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Ja
MediumCVSS 6.1No exploitEPSS 0%lightcms project · lightcmsMar 26, 2026
- CVE-2021-335523Monitor
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/S
MediumCVSS 5.4Proof of conceptEPSS 7%lightcms project · lightcmsFeb 24, 2021
- CVE-2024-2255921Monitor
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.
MediumCVSS 5.4No exploitEPSS 0%lightcms project · lightcmsJan 29, 2024
- CVE-2022-3300919Monitor
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploadin
MediumCVSS 4.8No exploitEPSS 1%lightcms project · lightcmsJun 27, 2022