Перейти к содержимому
Noroxi

Записи litespeedtech

34 опубликованных записей вендора litespeedtech.

Профиль для исследователя

Попали в KEV
2 · 5,9 %
С эксплойтом
4 · 11,8 %
Pre-auth RCE
0
С записью об исправлении
32,4 %
Медиана: публикация → KEV
4 дн.

Все записи

34 записей
  • CVE-2026-48172
    70На этой неделе

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %

    litespeedtech · litespeed cpanel plugin20 мая 2026 г.

  • CVE-2024-44000
    64На этой неделе

    WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability

    КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %

    litespeedtech · litespeed cache20 окт. 2024 г.

  • CVE-2026-54420
    64На этой неделе

    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP

    ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 1 %

    litespeedtech · litespeed cpanel plugin14 июн. 2026 г.

  • CVE-2024-28000
    59В плане

    WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 68 %

    litespeedtech · litespeed cache21 авг. 2024 г.

  • CVE-2023-40000
    40В плане

    WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability

    СредняяCVSS 6,1Proof of conceptEPSS 55 %

    litespeedtech · litespeed cache16 апр. 2024 г.

  • CVE-2022-30592
    40В плане

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    litespeedtech · lsquic11 мая 2022 г.

  • CVE-2020-5519
    39Наблюдать

    The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    litespeedtech · openlitespeed6 янв. 2020 г.

  • CVE-2024-50550
    39Наблюдать

    WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    litespeedtech · litespeed cache29 окт. 2024 г.

  • CVE-2024-25678
    39Наблюдать

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    litespeedtech · lsquic9 февр. 2024 г.

  • CVE-2010-2333
    38Наблюдать

    LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque

    СредняяCVSS 5,0Готовый эксплойтEPSS 60 %

    litespeedtech · litespeed web server18 июн. 2010 г.

  • CVE-2022-0073
    38Наблюдать

    Authenticated Remote Code Execution in OpenLiteSpeed Web Server

    ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %

    litespeedtech · openlitespeed27 окт. 2022 г.

  • CVE-2021-26758
    36Наблюдать

    Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    litespeedtech · openlitespeed7 апр. 2021 г.

  • CVE-2026-31386
    35Наблюдать

    OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.

    ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %

    litespeedtech · litespeed web server16 мар. 2026 г.

  • CVE-2022-0074
    35Наблюдать

    Privilege Escalation in OpenLiteSpeed Web Server

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    litespeedtech · openlitespeed27 окт. 2022 г.

  • CVE-2024-47637
    35Наблюдать

    WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    litespeedtech · litespeed cache16 окт. 2024 г.

  • CVE-2022-46800
    35Наблюдать

    WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    litespeedtech · litespeed cache25 мая 2023 г.

  • CVE-2015-3890
    30Наблюдать

    Use-after-free vulnerability in Open Litespeed before 1.3.10.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    litespeedtech · openlitespeed20 сент. 2017 г.

  • CVE-2025-54939
    30Наблюдать

    LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    litespeedtech · litespeed web adc1 авг. 2025 г.

  • CVE-2023-40518
    30Наблюдать

    LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    litespeedtech · openlitespeed14 авг. 2023 г.

  • CVE-2023-4372
    26Наблюдать

    LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 17 %

    litespeedtech · litespeed cache11 янв. 2024 г.

  • CVE-2018-19791
    26Наблюдать

    The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    litespeedtech · openlitespeed3 дек. 2018 г.

  • CVE-2018-19792
    26Наблюдать

    The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    litespeedtech · openlitespeed3 дек. 2018 г.

  • CVE-2024-47374
    24Наблюдать

    WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    litespeedtech · litespeed cache5 окт. 2024 г.

  • CVE-2021-24964
    24Наблюдать

    LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    litespeedtech · litespeed cache3 янв. 2022 г.

  • CVE-2020-29172
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    litespeedtech · litespeed cache25 дек. 2020 г.