Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lavalite HIGH 8.8
CVE-2025-70866

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the ad…

No fix yet
Fix from $1,950 2026-02-13
Lavalite MEDIUM 5.4
CVE-2025-71177

LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality…

Fix: after 10.1.0
Fix from $1,600 2026-01-23
Lavalite MEDIUM 6.1
CVE-2024-31828

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted…

No fix yet
Fix from $1,600 2024-04-26
Lavalite HIGH 7.5
CVE-2023-36983

LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.

No fix yet
Fix from $1,950 2023-08-01
Lavalite HIGH 7.5
CVE-2023-36984

LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.

No fix yet
Fix from $1,950 2023-08-01
Lavalite MEDIUM 5.4
CVE-2023-30124

LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2023-05-18
Lavalite CRITICAL 9.8
CVE-2023-27238

LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.

No fix yet
Fix from $2,300 2023-05-12
Lavalite MEDIUM 6.1
CVE-2023-27237

LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.

No fix yet
Fix from $1,600 2023-05-12
Lavalite HIGH 7.5
CVE-2022-42188

In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.

No fix yet
Fix from $1,950 2022-10-18
Lavalite MEDIUM 5.4
CVE-2020-36395

A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbit…

No fix yet
Fix from $1,600 2021-07-02
Lavalite MEDIUM 5.4
CVE-2020-36396

A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbi…

No fix yet
Fix from $1,600 2021-07-02
Lavalite MEDIUM 5.4
CVE-2020-36397

A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute…

No fix yet
Fix from $1,600 2021-07-02
Lavalite MEDIUM 5.4
CVE-2020-28124

Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.

No fix yet
Fix from $1,600 2021-04-14
Lavalite MEDIUM 6.1
CVE-2019-18883

XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.

No fix yet
Fix from $1,600 2019-11-13
Lavalite MEDIUM 5.4
CVE-2019-17434

LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.

Fix: after 5.7.0
Fix from $1,600 2019-10-10
Lavalite MEDIUM 5.4
CVE-2018-16551

LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.

No fix yet
Fix from $1,600 2018-09-05
Lavalite MEDIUM 5.4
CVE-2017-1000467

LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of s…

Mitigation only
Fix from $1,600 2018-01-03