Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-56704 LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An auth… Leptoncms No fix yet Fix from $1,9502025-12-09 HIGH 8.8 CVE-2024-29514 File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file. Leptoncms No fix yet Fix from $1,9502024-04-02 HIGH 8.8 CVE-2024-29515 File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the… Leptoncms No fix yet Fix from $1,9502024-03-25 HIGH 7.8 CVE-2024-24520 An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place. Leptoncms No fix yet Fix from $1,9502024-03-21 HIGH 7.2 CVE-2024-24399EPSS 16% An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the ba… Leptoncms No fix yet Fix from $1,9502024-01-25 MEDIUM 6.1 CVE-2020-24872 Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code. Leptoncms Mitigation only Fix from $1,6002023-08-11 MEDIUM 6.1 CVE-2020-12705 Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0. Leptoncms 4.6.0+ Fix from $1,6002020-05-07 MEDIUM 6.1 CVE-2020-12707 An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS … Lepton Cms Patch available Fix from $1,6002020-05-07 HIGH 7.5 CVE-2012-0998 Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files vi… Lepton after 1.1.3 Fix from $1,9502012-02-24 HIGH 7.5 CVE-2012-0999 SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id… Lepton after 1.1.3 Fix from $1,9502012-02-24