Medium severity4.8NVD Advisory· Published Dec 2, 2020· Updated Jun 17, 2026
CVE-2020-29240
CVE-2020-29240
Description
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:lepton-cms:leptoncms:4.7.0:*:*:*:*:*:*:*
- Lepton-CMS/Lepton-CMSdescription
- Range: =4.7.0
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49137nvdExploitThird Party AdvisoryVDB Entry
- lepton-cms.org/english/home.phpnvdProductVendor Advisory
News mentions
0No linked articles in our index yet.