VendorsLEPTON CMSlepton_cms4.5.0
Vulnerabilities

LEPTON CMS Lepton CMS 4.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-12707
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.
Published 2020-05-07 · Modified
6.11 PoCEPSS 0.012