VYPR

Lavalite

by Havalite

Source repositories

CVEs (19)

  • CVE-2023-27238CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.01

    LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.

  • CVE-2025-70866HigFeb 13, 2026
    risk 0.57cvss 8.8epss 0.00

    LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share…

  • CVE-2023-36984HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.

  • CVE-2023-36983HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.

  • CVE-2022-42188HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.

  • CVE-2024-31828MedApr 26, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

  • CVE-2023-27237MedMay 12, 2023
    risk 0.40cvss 6.1epss 0.01

    LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.

  • CVE-2019-18883MedNov 13, 2019
    risk 0.40cvss 6.1epss 0.01

    XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.

  • CVE-2025-71177MedJan 23, 2026
    risk 0.35cvss 5.4epss 0.00

    LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later…

  • CVE-2023-30124MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2020-36397MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.

  • CVE-2020-36396MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.

  • CVE-2020-36395MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.

  • CVE-2019-17434MedOct 10, 2019
    risk 0.35cvss 5.4epss 0.01

    LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.

  • CVE-2018-16551MedSep 5, 2018
    risk 0.35cvss 5.4epss 0.01

    LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.

  • CVE-2017-1000467MedJan 3, 2018
    risk 0.35cvss 5.4epss 0.01

    LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.

  • CVE-2020-23234MedJul 26, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".

  • CVE-2020-23700MedJul 7, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.

  • CVE-2020-28124MedApr 14, 2021
    risk 0.00cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.