CVE-2020-23234: Lavalite
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
Affected products
- Lavalite Lavalite: version 5.8.0 only
Published 2021-07-26. Last modified 2026-06-17.