Lepton-cms

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 13
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-56704

    LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerability by uploading a specially crafted ZIP/PHP file to execute arbitrary code.

    Last Modified: Dec 11, 2025
    Published: Dec 09, 2025

    CVE-2024-29514

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

    Last Modified: May 01, 2025
    Published: Apr 02, 2024

    CVE-2024-29515

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.

    Last Modified: May 01, 2025
    Published: Mar 25, 2024

    CVE-2024-24520

    An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

    Last Modified: Jul 09, 2026
    Published: Feb 29, 2024

    CVE-2024-24399

    An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

    Last Modified: Jun 05, 2025
    Published: Jan 25, 2024
    Items Per Page
    Lepton-Cms Vulnerabilities & Security CVEs | CVE-DB