Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

lepture — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting lepture. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents security vulnerabilities associated with the vendor Lepture, specifically covering general weakness types categorized under its product ecosystem. The collected data encompasses a wide range of security flaws found across Lepture’s applications, including password managers and authentication tools, spanning from early software releases through recent updates. This aggregation provides a chronological and technical view of how these vulnerabilities have been identified, disclosed, and mitigated over time, offering a comprehensive historical record for security researchers and administrators. Here, users can track Lepture’s security advisories to stay informed about critical patches and understand the specific weakness classes affecting their infrastructure. The page also allows for a detailed lookup of a specific product’s vulnerability history, enabling deeper analysis of recurring issues or systemic design flaws within the codebase. By centralizing this information, the resource supports informed decision-making regarding risk management and software procurement. It serves as a reference point for evaluating the security posture of Lepture’s solutions, helping stakeholders assess the impact of past incidents on current deployments. The content is structured to facilitate easy navigation through CVE records, technical details, and vendor responses, ensuring that users can efficiently correlate weaknesses with specific versions and release cycles. This approach promotes transparency and aids in the continuous improvement of software security practices within the organization’s environment.

Top products by lepture: mistune
CVE IDTitleCVSSSeverityPublished
CVE-2026-59927 Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files — mistuneCWE-674 5.3 Medium2026-07-08
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions — mistuneCWE-407 7.5 High2026-07-08
CVE-2026-59924 Mistune: Arbitrary File Read via Include directive path traversal — mistuneCWE-22 5.9 Medium2026-07-08
CVE-2026-59929 Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution — mistuneCWE-79 6.1 Medium2026-07-08
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs — mistuneCWE-407 7.5 High2026-07-08
CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive — mistuneCWE-79--2026-07-08
CVE-2026-59923 Mistune: XSS via percent-encoded javascript URI bypass in safe_url() — mistuneCWE-79 6.1 Medium2026-07-08
CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content — mistuneCWE-345 4.3 Medium2026-07-08
CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) — mistuneCWE-407 7.5 High2026-07-08
CVE-2026-49851 Mistune: Potential DoS via quadratic-time parsing in parse_link_text — mistuneCWE-400--2026-06-24
CVE-2026-44898 Mistune TOC Anchor Injection XSS — mistuneCWE-79 6.1 Medium2026-05-26
CVE-2026-44897 Mistune Heading ID Attribute Injection XSS — mistuneCWE-79 6.1 Medium2026-05-26
CVE-2026-44708 Mistune Math Plugin XSS Escape Bypass — mistuneCWE-79 6.1 Medium2026-05-26
CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability — mistuneCWE-79 4.7 Medium2026-05-26
CVE-2026-44896 Mistune: XSS via unescaped figclass/figwidth in Figure directive — mistuneCWE-79--2026-05-26
CVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles — mistuneCWE-1333 7.5AIHighAI2026-05-06

This page lists every published CVE security advisory associated with lepture. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.