Lavalite is a modestly represented content management and web-platform vendor whose vulnerability footprint concentrates in its core Lavalite product. Its disclosures recur through application-layer weakness classes including cross-site scripting, improper access control, path traversal, and HTTP request smuggling, patterns typical of web framework and CMS implementations that process user input and manage authentication boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lavalite over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27238CRITICAL LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning. | May 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-70866HIGH LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in throu | Feb 13, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-71177MEDIUM LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can suppl | Jan 23, 2026 | 5.4 | 25 | NO | NO |
CVE-2022-42188HIGH In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. | Oct 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-27237MEDIUM LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. | May 12, 2023 | 6.1 | 23 | NO | NO |
CVE-2023-36983HIGH LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | Aug 1, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36984HIGH LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | Aug 1, 2023 | 7.5 | 20 | NO | NO |
CVE-2019-18883MEDIUM XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field. | Nov 13, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-17434MEDIUM LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen. | Oct 10, 2019 | 5.4 | 19 | NO | NO |
CVE-2018-16551MEDIUM LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. | Sep 5, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lavalite.
Media articles that mention a CVE ID that affects a product developed by Lavalite — matched by CVE ID, not by vendor name.