Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Leptoncms HIGH 8.8
CVE-2025-56704

LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An auth…

No fix yet
Fix from $1,950 2025-12-09
Leptoncms HIGH 8.8
CVE-2024-29514

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

No fix yet
Fix from $1,950 2024-04-02
Leptoncms HIGH 8.8
CVE-2024-29515

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the…

No fix yet
Fix from $1,950 2024-03-25
Leptoncms HIGH 7.8
CVE-2024-24520

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

No fix yet
Fix from $1,950 2024-03-21
Leptoncms HIGH 7.2
CVE-2024-24399EPSS 16%

An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the ba…

No fix yet
Fix from $1,950 2024-01-25
Leptoncms MEDIUM 6.1
CVE-2020-24872

Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,600 2023-08-11
Leptoncms MEDIUM 6.1
CVE-2020-12705

Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.

Fix: 4.6.0+
Fix from $1,600 2020-05-07
Lepton Cms MEDIUM 6.1
CVE-2020-12707

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS …

Patch available
Fix from $1,600 2020-05-07
Lepton HIGH 7.5
CVE-2012-0998

Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files vi…

Fix: after 1.1.3
Fix from $1,950 2012-02-24
Lepton HIGH 7.5
CVE-2012-0999

SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id…

Fix: after 1.1.3
Fix from $1,950 2012-02-24