PT-2025-50106 · Leptoncms · Leptoncms

Published

2025-12-09

·

Updated

2025-12-22

·

CVE-2025-56704

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LeptonCMS version 7.3.0
Description LeptonCMS version 7.3.0 is affected by an arbitrary file upload issue due to insufficient validation of uploaded files. An authenticated attacker can exploit this by uploading a specially crafted ZIP/PHP file, potentially leading to arbitrary code execution.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict file upload functionality to trusted users only.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-56704

Affected Products

Leptoncms