CVE-2020-12705: Lepton-CMS Leptoncms

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.

Affected products

  • Lepton-CMS Leptoncms: before 4.6.0 (fixed in 4.6.0)

Published 2020-05-07. Last modified 2026-06-17.