Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-70866 LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the ad… Lavalite No fix yet Fix from $1,9502026-02-13 MEDIUM 5.4 CVE-2025-71177 LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality… Lavalite after 10.1.0 Fix from $1,6002026-01-23 MEDIUM 6.1 CVE-2024-31828 Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted… Lavalite No fix yet Fix from $1,6002024-04-26 HIGH 7.5 CVE-2023-36983 LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. Lavalite No fix yet Fix from $1,9502023-08-01 HIGH 7.5 CVE-2023-36984 LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. Lavalite No fix yet Fix from $1,9502023-08-01 MEDIUM 5.4 CVE-2023-30124 LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS). Lavalite No fix yet Fix from $1,6002023-05-18 CRITICAL 9.8 CVE-2023-27238 LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning. Lavalite No fix yet Fix from $2,3002023-05-12 MEDIUM 6.1 CVE-2023-27237 LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. Lavalite No fix yet Fix from $1,6002023-05-12 HIGH 7.5 CVE-2022-42188 In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. Lavalite No fix yet Fix from $1,9502022-10-18 MEDIUM 5.4 CVE-2020-36395 A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbit… Lavalite No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36396 A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbi… Lavalite No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-36397 A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute… Lavalite No fix yet Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2020-28124 Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field. Lavalite No fix yet Fix from $1,6002021-04-14 MEDIUM 6.1 CVE-2019-18883 XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field. Lavalite No fix yet Fix from $1,6002019-11-13 MEDIUM 5.4 CVE-2019-17434 LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen. Lavalite after 5.7.0 Fix from $1,6002019-10-10 MEDIUM 5.4 CVE-2018-16551 LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. Lavalite No fix yet Fix from $1,6002018-09-05 MEDIUM 5.4 CVE-2017-1000467 LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of s… Lavalite Mitigation only Fix from $1,6002018-01-03