VDB
Sign up
MEDIUM5.4

GHSA-h538-r9x6-rcmc

LavaLite vulnerable to Cross Site Scripting

Details

LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms
Introduced in: 0

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References