CVE-2023-27237: Lavalite

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.

Affected products

Published 2023-05-12. Last modified 2026-07-09.