CNNVD-202601-3957 Information
Jan 23, 2026
cve
CNNVD ID
CNNVD-202601-3957
Related CVE
- CNNVD Published: 2026-01-23
Description (Chinese)
LavaLite是Lavalite开源的一套轻量级内容管理系统。 LavaLite 10.1.0及之前版本存在跨站脚本漏洞,该漏洞源于包创建和搜索功能中存储的HTML或JavaScript未正确编码,可能导致存储型跨站脚本攻击。
Description (English)
Lavalite is a lightweight content management system open to Lavalite. LavaLite 10.1.0 and previous versions had a cross-site script loophole, which stemmed from the incorrect encoding of HTML or JavaScript stored in the package creation and search function, which could result in a storage-type cross-site script attack.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Lavalite
Published
2026-01-23
Last Modified
2026-02-24
References
https://github.com/LavaLite/cms/issues/420 https://lavalite.org/ https://www.vulncheck.com/advisories/lavalite-cms-stored-xss-via-package-creation-and-search https://access.redhat.com/security/cve/cve-2025-71177
Share on: