CVE-2025-71177 Details
Description
LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in package search results. When other users view search results that include the malicious package, the injected script executes in their browsers, potentially enabling session hijacking, credential theft, and unauthorized actions in the context of the victim.
A stored cross-site scripting vulnerability has been identified in LavaLite CMS versions 10.1.0 and prior. This issue arises in the package creation and search features, where authenticated users can input malicious HTML or JavaScript into the package Name or Description fields. The injected scripts are saved and later displayed in search results without proper output encoding. When other users view these search results, the malicious scripts execute in their browsers. This could lead to session hijacking, credential theft, and unauthorized actions on behalf of the victim.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LavaLite/cms/issues/420 | [email protected] | ExploitIssue Tracking |
| https://lavalite.org/ | [email protected] | Product |
| https://www.vulncheck.com/advisories/lavalite-cms-stored-xss-via-package-creation-and-search | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lavalite lavalite | <= 10.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | New CVE Received | [email protected] |