VYPR

LightCMS

by Eddy8

CVEs (3)

  • CVE-2021-27112CriApr 15, 2021
    risk 0.64cvss 9.8epss 0.02

    LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.

  • CVE-2026-29934MedMar 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.

  • CVE-2022-33009MedJun 27, 2022
    risk 0.31cvss 4.8epss 0.01

    A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.