İçeriğe atla
Noroxi

lepton-cms kayıtları

lepton-cms üreticisine ait 13 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

13 kayıt
  • CVE-2024-29514
    35İzleyin

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi

    YüksekCVSS 8,8İstismar yokEPSS %1

    lepton-cms · leptoncms2 Nis 2024

  • CVE-2024-29515
    35İzleyin

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP fi

    YüksekCVSS 8,8İstismar yokEPSS %1

    lepton-cms · leptoncms25 Mar 2024

  • CVE-2025-56704
    35İzleyin

    LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files

    YüksekCVSS 8,8İstismar yokEPSS %1

    lepton-cms · leptoncms9 Ara 2025

  • CVE-2024-24399
    33İzleyin

    An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code

    YüksekCVSS 7,2İstismar yokEPSS %16

    lepton-cms · leptoncms25 Oca 2024

  • CVE-2012-0998
    31İzleyin

    Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary

    YüksekCVSS 7,5İstismar yokEPSS %2

    lepton-cms · lepton24 Şub 2012

  • CVE-2024-24520
    31İzleyin

    An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

    YüksekCVSS 7,8İstismar yokEPSS %0

    lepton-cms · leptoncms20 Mar 2024

  • CVE-2012-0999
    30İzleyin

    SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the

    YüksekCVSS 7,5İstismar yokEPSS %1

    lepton-cms · lepton24 Şub 2012

  • CVE-2020-12707
    24İzleyin

    An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    lepton-cms · lepton cms7 May 2020

  • CVE-2020-12705
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.

    OrtaCVSS 6,1İstismar yokEPSS %1

    lepton-cms · leptoncms7 May 2020

  • CVE-2020-24872
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitra

    OrtaCVSS 6,1İstismar yokEPSS %1

    lepton-cms · leptoncms11 Ağu 2023

  • CVE-2020-29240
    20İzleyin

    Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).

    OrtaCVSS 4,8Kavram kanıtıEPSS %2

    lepton-cms · leptoncms2 Ara 2020

  • CVE-2012-1000
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitra

    OrtaCVSS 4,3İstismar yokEPSS %1

    lepton-cms · lepton24 Şub 2012

  • CVE-2011-3385
    17İzleyin

    Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers

    OrtaCVSS 4,3İstismar yokEPSS %1

    lepton-cms · lepton2 Eyl 2011