Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: lavalite Clear
ID Title
CVE-2025-71177 Cross-Site Scripting (XSS) in lavalite (CVE-2025-71177)
cross-site scripting in lavalite (CVE-2025-71177). Risk of unauthorized operations or information disclosure.
CVE-2024-31828 Cross-Site Scripting (XSS) in lavalite (CVE-2024-31828)
cross-site scripting in lavalite (CVE-2024-31828). Risk of unauthorized operations or information disclosure.
CVE-2023-27237 LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →