LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLavalite
APPLavalite9.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-70866HIGH8.8same product
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges...
CVE-2023-36984HIGH7.5same product
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36983HIGH7.5same product
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2022-42188HIGH7.5same product
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbi...
CVE-2025-71177MEDIUM5.1same product
LavaLite CMS w wersjach do 10.1.0 zawiera podatność stored XSS w funkcjonalności tworzenia pakietów i wyszukiw...