Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-24399

Disclosure Date: January 25, 2024 (last updated April 01, 2024)
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.
Attacker Value
Unknown

CVE-2020-24872

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-29240

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.
Attacker Value
Unknown

CVE-2020-12707

Disclosure Date: May 07, 2020 (last updated February 21, 2025)
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.
Attacker Value
Unknown

CVE-2020-12705

Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
Attacker Value
Unknown

CVE-2012-0998

Disclosure Date: February 24, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter.
0
Attacker Value
Unknown

CVE-2012-0999

Disclosure Date: February 24, 2012 (last updated October 04, 2023)
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.
0
Attacker Value
Unknown

CVE-2012-1000

Disclosure Date: February 24, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to admins/login/forgot/index.php, or the (2) display_name or (3) email parameter to account/preferences.php.
0
Attacker Value
Unknown

CVE-2011-3385

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307.
0