Vulnerabilities
Vulnerable Software
Lavalite:  >> Lavalite  >> 10.1.0  Security Vulnerabilities
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-02-13
LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in package search results. When other users view search results that include the malicious package, the injected script executes in their browsers, potentially enabling session hijacking, credential theft, and unauthorized actions in the context of the victim.
CVSS Score
5.4
EPSS Score
0.0
Published
2026-01-23
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-04-26


Contact Us

Shodan ® - All rights reserved