Lepton CMS is a content-management system with a modest but notable footprint in the vulnerability landscape, with its disclosures centered on the core Lepton product itself. The vendor's vulnerability profile does not point to a durable pattern of particular weakness classes; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lepton Cms over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56704HIGH LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit | Dec 9, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-24399HIGH An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php langu | Jan 25, 2024 | 7.2 | 27 | NO | NO |
CVE-2020-29240MEDIUM Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-P | Dec 2, 2020 | 4.8 | 27 | NO | YES |
CVE-2020-12707MEDIUM An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elem | May 7, 2020 | 6.1 | 25 | NO | YES |
CVE-2024-29514HIGH File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file. | Apr 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-29515HIGH File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php compon | Mar 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24520HIGH An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place. | Mar 21, 2024 | 7.8 | 24 | NO | NO |
CVE-2012-0998HIGH Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the languag | Feb 24, 2012 | 7.5 | 24 | NO | NO |
CVE-2012-0999HIGH SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter. | Feb 24, 2012 | 7.5 | 22 | NO | NO |
CVE-2020-12705MEDIUM Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0. | May 7, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lepton Cms.
Media articles that mention a CVE ID that affects a product developed by Lepton Cms — matched by CVE ID, not by vendor name.