VendorsLEPTON CMSleptoncms4.7.0
Vulnerabilities

LEPTON CMS Lepton-CMS LeptonCMS 4.7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-24872
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.
Published 2023-08-11 · Modified
6.1EPSS 0.005
CVE-2020-29240
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.
Published 2020-12-02 · Modified
4.81 PoCEPSS 0.017