Lemon
Mossle · 4 CVEs
CVE-2025-9406
MEDIUM
xuhuisheng lemon CmsArticleController.java uploadImage unrestricted upload
Aug 25, 2025
CVE-2020-20598
MEDIUM
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitr…
Dec 22, 2021
CVE-2020-20597
MEDIUM
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.1…
Dec 22, 2021
CVE-2018-18315
HIGH
com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFi…
Oct 15, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-9406 | xuhuisheng lemon CmsArticleController.java uploadImage unrestricted upload | MEDIUM | 0.38% | Aug 25, 2025 |
| CVE-2020-20598 | A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. | MEDIUM | 0.72% | Dec 22, 2021 |
| CVE-2020-20597 | A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrar… | MEDIUM | 0.72% | Dec 22, 2021 |
| CVE-2018-18315 | com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks… | HIGH | 1.18% | Oct 15, 2018 |
Showing 1 to 4 of 4 CVEs