Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lepton Cms

First CVE: Sep 2, 2011Active for: 15 yearsTotal CVEs: 26

Lepton CMS is a content-management system with a modest but notable footprint in the vulnerability landscape, with its disclosures centered on the core Lepton product itself. The vendor's vulnerability profile does not point to a durable pattern of particular weakness classes; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lepton Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2011
14 years ago
Most Recent CVE
Dec 9, 2025
228 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-56704HIGH
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit
Dec 9, 20258.829NONO
CVE-2024-24399HIGH
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php langu
Jan 25, 20247.227NONO
CVE-2020-29240MEDIUM
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-P
Dec 2, 20204.827NOYES
CVE-2020-12707MEDIUM
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elem
May 7, 20206.125NOYES
CVE-2024-29514HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.
Apr 2, 20248.824NONO
CVE-2024-29515HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php compon
Mar 25, 20248.824NONO
CVE-2024-24520HIGH
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
Mar 21, 20247.824NONO
CVE-2012-0998HIGH
Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the languag
Feb 24, 20127.524NONO
CVE-2012-0999HIGH
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.
Feb 24, 20127.522NONO
CVE-2020-12705MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
May 7, 20206.121NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
54%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (7.7%)
Network8 (61.5%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High0 (0.0%)
Unknown4 (30.8%)
User Interaction
None5 (38.5%)
Unknown4 (30.8%)
Required4 (30.8%)
Privileges Required
Low4 (30.8%)
High2 (15.4%)
None3 (23.1%)
Unknown4 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
15.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lepton Cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lepton Cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lepton Cms's Products

View all 2 CNAs →

Top CWEs