CVE-2024-31828: Lavalite

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

Affected products

Published 2024-04-26. Last modified 2026-08-24.