
CVE-2025-70866 LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by lo… https://www.cve.org/CVERecord?id=CVE-2025-70866
Post summary
LavaLite CMS 10.1.0 has an Incorrect Access Control flaw allowing authenticated users with low-level privileges to access the admin backend. The advisory provides basic technical details but no patch or PoC.

