CVE-2024-24520: Lepton-CMS Leptoncms

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

Affected products

Published 2024-03-21. Last modified 2026-07-09.