Записи lepton-cms
13 опубликованных записей вендора lepton-cms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2024-29514Эксплойта нет | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | Высокая8,8 | — | 1,3 % | 2 апр. 2024 г. |
35Наблюдать | CVE-2024-29515Эксплойта нет | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | Высокая8,8 | — | 1,2 % | 25 мар. 2024 г. |
35Наблюдать | CVE-2025-56704Эксплойта нет | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded fileslepton-cms · leptoncms · CWE-434 | Высокая8,8 | — | 0,8 % | 9 дек. 2025 г. |
33Наблюдать | CVE-2024-24399Эксплойта нет | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code lepton-cms · leptoncms · CWE-434 | Высокая7,2 | — | 15,6 % | 25 янв. 2024 г. |
31Наблюдать | CVE-2012-0998Эксплойта нет | Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrarylepton-cms · lepton · CWE-22 | Высокая7,5 | — | 1,9 % | 24 февр. 2012 г. |
31Наблюдать | CVE-2024-24520Эксплойта нет | An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.lepton-cms · leptoncms · CWE-94 | Высокая7,8 | — | 0,4 % | 20 мар. 2024 г. |
30Наблюдать | CVE-2012-0999Эксплойта нет | SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via thelepton-cms · lepton · CWE-89 | Высокая7,5 | — | 1,3 % | 24 февр. 2012 г. |
24Наблюдать | CVE-2020-12707Proof of concept | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.lepton-cms · lepton cms · CWE-79 | Средняя6,1 | — | 1,2 % | 7 мая 2020 г. |
24Наблюдать | CVE-2020-12705Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.lepton-cms · leptoncms · CWE-79 | Средняя6,1 | — | 0,6 % | 7 мая 2020 г. |
24Наблюдать | CVE-2020-24872Эксплойта нет | Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitralepton-cms · leptoncms · CWE-79 | Средняя6,1 | — | 0,5 % | 11 авг. 2023 г. |
20Наблюдать | CVE-2020-29240Proof of concept | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).lepton-cms · leptoncms · CWE-79 | Средняя4,8 | — | 1,7 % | 2 дек. 2020 г. |
17Наблюдать | CVE-2012-1000Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitralepton-cms · lepton · CWE-79 | Средняя4,3 | — | 1,2 % | 24 февр. 2012 г. |
17Наблюдать | CVE-2011-3385Эксплойта нет | Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers lepton-cms · lepton · CWE-79 | Средняя4,3 | — | 0,8 % | 2 сент. 2011 г. |
- CVE-2024-2951435Наблюдать
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %lepton-cms · leptoncms2 апр. 2024 г.
- CVE-2024-2951535Наблюдать
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %lepton-cms · leptoncms25 мар. 2024 г.
- CVE-2025-5670435Наблюдать
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %lepton-cms · leptoncms9 дек. 2025 г.
- CVE-2024-2439933Наблюдать
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code
ВысокаяCVSS 7,2Эксплойта нетEPSS 16 %lepton-cms · leptoncms25 янв. 2024 г.
- CVE-2012-099831Наблюдать
Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lepton-cms · lepton24 февр. 2012 г.
- CVE-2024-2452031Наблюдать
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %lepton-cms · leptoncms20 мар. 2024 г.
- CVE-2012-099930Наблюдать
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lepton-cms · lepton24 февр. 2012 г.
- CVE-2020-1270724Наблюдать
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.
СредняяCVSS 6,1Proof of conceptEPSS 1 %lepton-cms · lepton cms7 мая 2020 г.
- CVE-2020-1270524Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %lepton-cms · leptoncms7 мая 2020 г.
- CVE-2020-2487224Наблюдать
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitra
СредняяCVSS 6,1Эксплойта нетEPSS 1 %lepton-cms · leptoncms11 авг. 2023 г.
- CVE-2020-2924020Наблюдать
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).
СредняяCVSS 4,8Proof of conceptEPSS 2 %lepton-cms · leptoncms2 дек. 2020 г.
- CVE-2012-100017Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitra
СредняяCVSS 4,3Эксплойта нетEPSS 1 %lepton-cms · lepton24 февр. 2012 г.
- CVE-2011-338517Наблюдать
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers
СредняяCVSS 4,3Эксплойта нетEPSS 1 %lepton-cms · lepton2 сент. 2011 г.