CVE-2024-24520
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
CVSS
7.8
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Mar 21, 2024 · Last modified: Jul 9, 2026 · CWE-94
0.4%EPSS · 30 days0.4%
2026-06-302026-07-19
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
- github.comhttps://github.com/capture0x/leptoncms
- github.comhttps://github.com/xF9979/LEPTON-CMS
- packetstormsecurity.comhttps://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html
- www.exploit-db.comhttps://www.exploit-db.com/exploits/51949
- github.comhttps://github.com/capture0x/leptoncms
- github.comhttps://github.com/xF9979/LEPTON-CMS
- packetstormsecurity.comhttps://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html
- www.exploit-db.comhttps://www.exploit-db.com/exploits/51949
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32489.8 CRI100.0%
KEV—80Langflow Missing Authentication Vulnerability6dCVE-2026-341978.8 HIG99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability5dCVE-2026-154107.2 HIG71.1%
KEV—71SonicWall SMA1000 Appliances Code Injection Vulnerability4dCVE-2025-670389.8 CRI55.3%
KEV—67Lantronix EDS5000 Code Injection Vulnerability14dCVE-2021-416539.8 CRI99.5%
——30The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.11dCVE-2023-362558.8 HIG99.0%
——30An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.11d