Skip to content
Noroxi

litespeedtech records

34 published records for vendor litespeedtech.

Researcher profile

Entered KEV
2 · 5.9%
Weaponized
4 · 11.8%
Pre-auth RCE
0
With a fix record
32.4%
Median publish → KEV
4 days

All records

34 records
  • CVE-2026-48172
    70This week

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.

    CriticalCVSS 10.0KEVWeaponizedEPSS 1%

    litespeedtech · litespeed cpanel pluginMay 20, 2026

  • CVE-2024-44000
    64This week

    WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 82%

    litespeedtech · litespeed cacheOct 20, 2024

  • CVE-2026-54420
    64This week

    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP

    HighCVSS 8.5KEVWeaponizedEPSS 1%

    litespeedtech · litespeed cpanel pluginJun 14, 2026

  • WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    litespeedtech · litespeed cacheAug 21, 2024

  • WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 55%

    litespeedtech · litespeed cacheApr 16, 2024

  • liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    litespeedtech · lsquicMay 11, 2022

  • CVE-2020-5519
    39Monitor

    The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext

    CriticalCVSS 9.8No exploitEPSS 1%

    litespeedtech · openlitespeedJan 6, 2020

  • WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    litespeedtech · litespeed cacheOct 29, 2024

  • In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

    CriticalCVSS 9.8No exploitEPSS 0%

    litespeedtech · lsquicFeb 9, 2024

  • CVE-2010-2333
    38Monitor

    LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque

    MediumCVSS 5.0WeaponizedEPSS 60%

    litespeedtech · litespeed web serverJun 18, 2010

  • CVE-2022-0073
    38Monitor

    Authenticated Remote Code Execution in OpenLiteSpeed Web Server

    HighCVSS 8.8No exploitEPSS 9%

    litespeedtech · openlitespeedOct 27, 2022

  • Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec

    HighCVSS 8.8No exploitEPSS 3%

    litespeedtech · openlitespeedApr 7, 2021

  • OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.

    HighCVSS 8.6No exploitEPSS 2%

    litespeedtech · litespeed web serverMar 16, 2026

  • CVE-2022-0074
    35Monitor

    Privilege Escalation in OpenLiteSpeed Web Server

    HighCVSS 8.8No exploitEPSS 1%

    litespeedtech · openlitespeedOct 27, 2022

  • WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    litespeedtech · litespeed cacheOct 16, 2024

  • WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    litespeedtech · litespeed cacheMay 25, 2023

  • CVE-2015-3890
    30Monitor

    Use-after-free vulnerability in Open Litespeed before 1.3.10.

    HighCVSS 7.5No exploitEPSS 1%

    litespeedtech · openlitespeedSep 20, 2017

  • LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

    HighCVSS 7.5Proof of conceptEPSS 1%

    litespeedtech · litespeed web adcAug 1, 2025

  • LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

    HighCVSS 7.5No exploitEPSS 1%

    litespeedtech · openlitespeedAug 14, 2023

  • CVE-2023-4372
    26Monitor

    LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 17%

    litespeedtech · litespeed cacheJan 11, 2024

  • The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif

    MediumCVSS 6.5No exploitEPSS 1%

    litespeedtech · openlitespeedDec 3, 2018

  • The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un

    MediumCVSS 6.7No exploitEPSS 0%

    litespeedtech · openlitespeedDec 3, 2018

  • WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 1%

    litespeedtech · litespeed cacheOct 5, 2024

  • LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS

    MediumCVSS 6.1No exploitEPSS 1%

    litespeedtech · litespeed cacheJan 3, 2022

  • A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti

    MediumCVSS 6.1No exploitEPSS 1%

    litespeedtech · litespeed cacheDec 25, 2020