← Back

Lightcms

lightcms

Vendor: Lightcms Project • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lightcms Project
1Lightcms
Jun 17, 2026
Mar 26, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in...Show more
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.Show less
1Lightcms Project
1Lightcms
Jun 17, 2026
Jan 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.
1Lightcms Project
1Lightcms
Jun 17, 2026
Mar 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
1Lightcms Project
1Lightcms
Jul 9, 2026
Jun 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
1Lightcms Project
1Lightcms
Jun 17, 2026
Apr 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
1Lightcms Project
1Lightcms
Jun 17, 2026
Feb 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.