lepton-cms kayıtları
lepton-cms üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2024-29514İstismar yok | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | Yüksek8,8 | — | %1,3 | 2 Nis 2024 |
35İzleyin | CVE-2024-29515İstismar yok | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP filepton-cms · leptoncms · CWE-434 | Yüksek8,8 | — | %1,2 | 25 Mar 2024 |
35İzleyin | CVE-2025-56704İstismar yok | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded fileslepton-cms · leptoncms · CWE-434 | Yüksek8,8 | — | %0,8 | 9 Ara 2025 |
33İzleyin | CVE-2024-24399İstismar yok | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code lepton-cms · leptoncms · CWE-434 | Yüksek7,2 | — | %15,6 | 25 Oca 2024 |
31İzleyin | CVE-2012-0998İstismar yok | Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrarylepton-cms · lepton · CWE-22 | Yüksek7,5 | — | %1,9 | 24 Şub 2012 |
31İzleyin | CVE-2024-24520İstismar yok | An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.lepton-cms · leptoncms · CWE-94 | Yüksek7,8 | — | %0,4 | 20 Mar 2024 |
30İzleyin | CVE-2012-0999İstismar yok | SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via thelepton-cms · lepton · CWE-89 | Yüksek7,5 | — | %1,3 | 24 Şub 2012 |
24İzleyin | CVE-2020-12707Kavram kanıtı | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.lepton-cms · lepton cms · CWE-79 | Orta6,1 | — | %1,2 | 7 May 2020 |
24İzleyin | CVE-2020-12705İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.lepton-cms · leptoncms · CWE-79 | Orta6,1 | — | %0,6 | 7 May 2020 |
24İzleyin | CVE-2020-24872İstismar yok | Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitralepton-cms · leptoncms · CWE-79 | Orta6,1 | — | %0,5 | 11 Ağu 2023 |
20İzleyin | CVE-2020-29240Kavram kanıtı | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).lepton-cms · leptoncms · CWE-79 | Orta4,8 | — | %1,7 | 2 Ara 2020 |
17İzleyin | CVE-2012-1000İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitralepton-cms · lepton · CWE-79 | Orta4,3 | — | %1,2 | 24 Şub 2012 |
17İzleyin | CVE-2011-3385İstismar yok | Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers lepton-cms · lepton · CWE-79 | Orta4,3 | — | %0,8 | 2 Eyl 2011 |
- CVE-2024-2951435İzleyin
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
YüksekCVSS 8,8İstismar yokEPSS %1lepton-cms · leptoncms2 Nis 2024
- CVE-2024-2951535İzleyin
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi
YüksekCVSS 8,8İstismar yokEPSS %1lepton-cms · leptoncms25 Mar 2024
- CVE-2025-5670435İzleyin
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files
YüksekCVSS 8,8İstismar yokEPSS %1lepton-cms · leptoncms9 Ara 2025
- CVE-2024-2439933İzleyin
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code
YüksekCVSS 7,2İstismar yokEPSS %16lepton-cms · leptoncms25 Oca 2024
- CVE-2012-099831İzleyin
Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary
YüksekCVSS 7,5İstismar yokEPSS %2lepton-cms · lepton24 Şub 2012
- CVE-2024-2452031İzleyin
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
YüksekCVSS 7,8İstismar yokEPSS %0lepton-cms · leptoncms20 Mar 2024
- CVE-2012-099930İzleyin
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5İstismar yokEPSS %1lepton-cms · lepton24 Şub 2012
- CVE-2020-1270724İzleyin
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.
OrtaCVSS 6,1Kavram kanıtıEPSS %1lepton-cms · lepton cms7 May 2020
- CVE-2020-1270524İzleyin
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
OrtaCVSS 6,1İstismar yokEPSS %1lepton-cms · leptoncms7 May 2020
- CVE-2020-2487224İzleyin
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitra
OrtaCVSS 6,1İstismar yokEPSS %1lepton-cms · leptoncms11 Ağu 2023
- CVE-2020-2924020İzleyin
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).
OrtaCVSS 4,8Kavram kanıtıEPSS %2lepton-cms · leptoncms2 Ara 2020
- CVE-2012-100017İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitra
OrtaCVSS 4,3İstismar yokEPSS %1lepton-cms · lepton24 Şub 2012
- CVE-2011-338517İzleyin
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers
OrtaCVSS 4,3İstismar yokEPSS %1lepton-cms · lepton2 Eyl 2011