MEDIUM5.4
GHSA-h538-r9x6-rcmc
LavaLite vulnerable to Cross Site Scripting
Details
LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
Introduced in:
0No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.