VendorsLightCMS Projectlightcms2.0
Vulnerabilities

LightCMS Project LightCMS 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-29934
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.
Published 2026-03-26 · Modified
6.1EPSS 0.003
CVE-2024-22559
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.
Published 2024-01-29 · Modified
5.4EPSS 0.003