{"id":"CVE-2020-12707","details":"An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.","modified":"2026-07-09T05:13:32.868950Z","published":"2020-05-07T20:15:12.500Z","references":[{"type":"FIX","url":"https://gitlab.com/lepton-cms/LEPTON/-/commit/52215f708395a329c9e17ea33bfc6762d4efccbb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/lepton-cms/LEPTON","events":[{"introduced":"2ee628239a4c8147a67e41e7c6ee2b755c9c4f0b"},{"last_affected":"2ee628239a4c8147a67e41e7c6ee2b755c9c4f0b"}],"database_specific":{"cpe":"cpe:2.3:a:lepton-cms:lepton_cms:4.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.5.0"},{"last_affected":"4.5.0"}],"source":"CPE_STRING"}}],"versions":["4.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12707.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/lepton-cms/lepton","events":[{"introduced":"0"},{"fixed":"52215f708395a329c9e17ea33bfc6762d4efccbb"}],"database_specific":{"source":"REFERENCES"}}],"versions":["4.5.0","4.4.0","4.3.0","4.2.0","4.1.0","4.0.0","3.0.1","3.0.0","3.0.0-RC1","2.4.0","2.3.0","2.2.2","2.1.0","2.0.0_stable","2.0.0-RC","2.0.0","2.0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12707.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}