litespeedtech records
34 published records for vendor litespeedtech.
Researcher profile
- Entered KEV
- 2 · 5.9%
- Weaponized
- 4 · 11.8%
- Pre-auth RCE
- 0
- With a fix record
- 32.4%
- Median publish → KEV
- 4 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-266 Incorrect Privilege Assignment3
- CWE-20 Improper Input Validation3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-23 Relative Path Traversal1
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
70This week | CVE-2026-48172Weaponized | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.litespeedtech · litespeed cpanel plugin · CWE-266 | Critical10.0 | KEV | 1.0% | May 20, 2026 |
64This week | CVE-2024-44000Weaponized | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Critical9.8 | — | 82.3% | Oct 20, 2024 |
64This week | CVE-2026-54420Weaponized | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPlitespeedtech · litespeed cpanel plugin · CWE-61 | High8.5 | KEV | 0.8% | Jun 14, 2026 |
59Plan | CVE-2024-28000Proof of concept | WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Critical9.8 | — | 68.3% | Aug 21, 2024 |
40Plan | CVE-2023-40000Proof of concept | WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Medium6.1 | — | 54.9% | Apr 16, 2024 |
40Plan | CVE-2022-30592Proof of concept | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.litespeedtech · lsquic · CWE-476 | Critical9.8 | — | 3.2% | May 11, 2022 |
39Monitor | CVE-2020-5519No exploit | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Extlitespeedtech · openlitespeed · CWE-20 | Critical9.8 | — | 1.2% | Jan 6, 2020 |
39Monitor | CVE-2024-50550No exploit | WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Critical9.8 | — | 0.9% | Oct 29, 2024 |
39Monitor | CVE-2024-25678No exploit | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.litespeedtech · lsquic · CWE-354 | Critical9.8 | — | 0.4% | Feb 9, 2024 |
38Monitor | CVE-2010-2333Weaponized | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP requelitespeedtech · litespeed web server · CWE-200 | Medium5.0 | — | 60.2% | Jun 18, 2010 |
38Monitor | CVE-2022-0073No exploit | Authenticated Remote Code Execution in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-20 | High8.8 | — | 8.8% | Oct 27, 2022 |
36Monitor | CVE-2021-26758No exploit | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execlitespeedtech · openlitespeed · CWE-269 | High8.8 | — | 2.7% | Apr 7, 2021 |
35Monitor | CVE-2026-31386No exploit | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.litespeedtech · litespeed web server · CWE-78 | High8.6 | — | 2.1% | Mar 16, 2026 |
35Monitor | CVE-2022-0074No exploit | Privilege Escalation in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-426 | High8.8 | — | 1.2% | Oct 27, 2022 |
35Monitor | CVE-2024-47637No exploit | WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerabilitylitespeedtech · litespeed cache · CWE-23 | High8.8 | — | 0.6% | Oct 16, 2024 |
35Monitor | CVE-2022-46800No exploit | WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)litespeedtech · litespeed cache · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
30Monitor | CVE-2015-3890No exploit | Use-after-free vulnerability in Open Litespeed before 1.3.10.litespeedtech · openlitespeed · CWE-416 | High7.5 | — | 1.1% | Sep 20, 2017 |
30Monitor | CVE-2025-54939Proof of concept | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.litespeedtech · litespeed web adc · CWE-770 | High7.5 | — | 0.8% | Aug 1, 2025 |
30Monitor | CVE-2023-40518No exploit | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.litespeedtech · openlitespeed | High7.5 | — | 0.7% | Aug 14, 2023 |
26Monitor | CVE-2023-4372No exploit | LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodelitespeedtech · litespeed cache · CWE-79 | Medium5.4 | — | 16.8% | Jan 11, 2024 |
26Monitor | CVE-2018-19791No exploit | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to ampliflitespeedtech · openlitespeed · CWE-20 | Medium6.5 | — | 1.2% | Dec 3, 2018 |
26Monitor | CVE-2018-19792No exploit | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unlitespeedtech · openlitespeed · CWE-119 | Medium6.7 | — | 0.4% | Dec 3, 2018 |
24Monitor | CVE-2024-47374Proof of concept | WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Medium6.1 | — | 1.4% | Oct 5, 2024 |
24Monitor | CVE-2021-24964No exploit | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSSlitespeedtech · litespeed cache · CWE-79 | Medium6.1 | — | 1.2% | Jan 3, 2022 |
24Monitor | CVE-2020-29172No exploit | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP settilitespeedtech · litespeed cache · CWE-79 | Medium6.1 | — | 0.9% | Dec 25, 2020 |
- CVE-2026-4817270This week
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.
CriticalCVSS 10.0KEVWeaponizedEPSS 1%litespeedtech · litespeed cpanel pluginMay 20, 2026
- CVE-2024-4400064This week
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
CriticalCVSS 9.8WeaponizedEPSS 82%litespeedtech · litespeed cacheOct 20, 2024
- CVE-2026-5442064This week
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP
HighCVSS 8.5KEVWeaponizedEPSS 1%litespeedtech · litespeed cpanel pluginJun 14, 2026
- CVE-2024-2800059Plan
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 68%litespeedtech · litespeed cacheAug 21, 2024
- CVE-2023-4000040Plan
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
MediumCVSS 6.1Proof of conceptEPSS 55%litespeedtech · litespeed cacheApr 16, 2024
- CVE-2022-3059240Plan
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
CriticalCVSS 9.8Proof of conceptEPSS 3%litespeedtech · lsquicMay 11, 2022
- CVE-2020-551939Monitor
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext
CriticalCVSS 9.8No exploitEPSS 1%litespeedtech · openlitespeedJan 6, 2020
- CVE-2024-5055039Monitor
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%litespeedtech · litespeed cacheOct 29, 2024
- CVE-2024-2567839Monitor
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
CriticalCVSS 9.8No exploitEPSS 0%litespeedtech · lsquicFeb 9, 2024
- CVE-2010-233338Monitor
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque
MediumCVSS 5.0WeaponizedEPSS 60%litespeedtech · litespeed web serverJun 18, 2010
- CVE-2022-007338Monitor
Authenticated Remote Code Execution in OpenLiteSpeed Web Server
HighCVSS 8.8No exploitEPSS 9%litespeedtech · openlitespeedOct 27, 2022
- CVE-2021-2675836Monitor
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec
HighCVSS 8.8No exploitEPSS 3%litespeedtech · openlitespeedApr 7, 2021
- CVE-2026-3138635Monitor
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.
HighCVSS 8.6No exploitEPSS 2%litespeedtech · litespeed web serverMar 16, 2026
- CVE-2022-007435Monitor
Privilege Escalation in OpenLiteSpeed Web Server
HighCVSS 8.8No exploitEPSS 1%litespeedtech · openlitespeedOct 27, 2022
- CVE-2024-4763735Monitor
WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
HighCVSS 8.8No exploitEPSS 1%litespeedtech · litespeed cacheOct 16, 2024
- CVE-2022-4680035Monitor
WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%litespeedtech · litespeed cacheMay 25, 2023
- CVE-2015-389030Monitor
Use-after-free vulnerability in Open Litespeed before 1.3.10.
HighCVSS 7.5No exploitEPSS 1%litespeedtech · openlitespeedSep 20, 2017
- CVE-2025-5493930Monitor
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
HighCVSS 7.5Proof of conceptEPSS 1%litespeedtech · litespeed web adcAug 1, 2025
- CVE-2023-4051830Monitor
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
HighCVSS 7.5No exploitEPSS 1%litespeedtech · openlitespeedAug 14, 2023
- CVE-2023-437226Monitor
LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 17%litespeedtech · litespeed cacheJan 11, 2024
- CVE-2018-1979126Monitor
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif
MediumCVSS 6.5No exploitEPSS 1%litespeedtech · openlitespeedDec 3, 2018
- CVE-2018-1979226Monitor
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un
MediumCVSS 6.7No exploitEPSS 0%litespeedtech · openlitespeedDec 3, 2018
- CVE-2024-4737424Monitor
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1Proof of conceptEPSS 1%litespeedtech · litespeed cacheOct 5, 2024
- CVE-2021-2496424Monitor
LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS
MediumCVSS 6.1No exploitEPSS 1%litespeedtech · litespeed cacheJan 3, 2022
- CVE-2020-2917224Monitor
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti
MediumCVSS 6.1No exploitEPSS 1%litespeedtech · litespeed cacheDec 25, 2020