📦 Lavalite

by Lavalite

🔍 What is Lavalite?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-27238

CRITICAL CVSS 9.8 May 12, 2023

LavaLite CMS v9.0.0 contains a web cache poisoning vulnerability that allows attackers to inject malicious content into web caches. This can lead to users receiving poisoned content when accessing cac...

CVE-2025-70866

HIGH CVSS 8.8 Feb 13, 2026

LavaLite CMS 10.1.0 has an access control vulnerability where authenticated users with low-level privileges can bypass role restrictions and access the admin backend. This occurs because the admin and...

CVE-2023-36984

HIGH CVSS 7.5 Aug 1, 2023

LavaLite CMS v9.0.0 contains a sensitive data exposure vulnerability that allows attackers to access confidential information without proper authentication. This affects all installations running the ...

CVE-2025-71177

MEDIUM CVSS 5.4 Jan 23, 2026

LavaLite CMS versions up to 10.1.0 contain a stored cross-site scripting vulnerability where authenticated users can inject malicious scripts into package Name or Description fields. These scripts exe...