Записи litespeedtech
34 опубликованных записей вендора litespeedtech.
Профиль для исследователя
- Попали в KEV
- 2 · 5,9 %
- С эксплойтом
- 4 · 11,8 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 32,4 %
- Медиана: публикация → KEV
- 4 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-266 Incorrect Privilege Assignment3
- CWE-20 Improper Input Validation3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-23 Relative Path Traversal1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
70На этой неделе | CVE-2026-48172Готовый эксплойт | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.litespeedtech · litespeed cpanel plugin · CWE-266 | Критическая10,0 | KEV | 1,0 % | 20 мая 2026 г. |
64На этой неделе | CVE-2024-44000Готовый эксплойт | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Критическая9,8 | — | 82,3 % | 20 окт. 2024 г. |
64На этой неделе | CVE-2026-54420Готовый эксплойт | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPlitespeedtech · litespeed cpanel plugin · CWE-61 | Высокая8,5 | KEV | 0,8 % | 14 июн. 2026 г. |
59В плане | CVE-2024-28000Proof of concept | WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Критическая9,8 | — | 68,3 % | 21 авг. 2024 г. |
40В плане | CVE-2023-40000Proof of concept | WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Средняя6,1 | — | 54,9 % | 16 апр. 2024 г. |
40В плане | CVE-2022-30592Proof of concept | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.litespeedtech · lsquic · CWE-476 | Критическая9,8 | — | 3,2 % | 11 мая 2022 г. |
39Наблюдать | CVE-2020-5519Эксплойта нет | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Extlitespeedtech · openlitespeed · CWE-20 | Критическая9,8 | — | 1,2 % | 6 янв. 2020 г. |
39Наблюдать | CVE-2024-50550Эксплойта нет | WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Критическая9,8 | — | 0,9 % | 29 окт. 2024 г. |
39Наблюдать | CVE-2024-25678Эксплойта нет | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.litespeedtech · lsquic · CWE-354 | Критическая9,8 | — | 0,4 % | 9 февр. 2024 г. |
38Наблюдать | CVE-2010-2333Готовый эксплойт | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP requelitespeedtech · litespeed web server · CWE-200 | Средняя5,0 | — | 60,2 % | 18 июн. 2010 г. |
38Наблюдать | CVE-2022-0073Эксплойта нет | Authenticated Remote Code Execution in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-20 | Высокая8,8 | — | 8,8 % | 27 окт. 2022 г. |
36Наблюдать | CVE-2021-26758Эксплойта нет | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execlitespeedtech · openlitespeed · CWE-269 | Высокая8,8 | — | 2,7 % | 7 апр. 2021 г. |
35Наблюдать | CVE-2026-31386Эксплойта нет | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.litespeedtech · litespeed web server · CWE-78 | Высокая8,6 | — | 2,1 % | 16 мар. 2026 г. |
35Наблюдать | CVE-2022-0074Эксплойта нет | Privilege Escalation in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-426 | Высокая8,8 | — | 1,2 % | 27 окт. 2022 г. |
35Наблюдать | CVE-2024-47637Эксплойта нет | WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerabilitylitespeedtech · litespeed cache · CWE-23 | Высокая8,8 | — | 0,6 % | 16 окт. 2024 г. |
35Наблюдать | CVE-2022-46800Эксплойта нет | WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)litespeedtech · litespeed cache · CWE-352 | Высокая8,8 | — | 0,3 % | 25 мая 2023 г. |
30Наблюдать | CVE-2015-3890Эксплойта нет | Use-after-free vulnerability in Open Litespeed before 1.3.10.litespeedtech · openlitespeed · CWE-416 | Высокая7,5 | — | 1,1 % | 20 сент. 2017 г. |
30Наблюдать | CVE-2025-54939Proof of concept | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.litespeedtech · litespeed web adc · CWE-770 | Высокая7,5 | — | 0,8 % | 1 авг. 2025 г. |
30Наблюдать | CVE-2023-40518Эксплойта нет | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.litespeedtech · openlitespeed | Высокая7,5 | — | 0,7 % | 14 авг. 2023 г. |
26Наблюдать | CVE-2023-4372Эксплойта нет | LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodelitespeedtech · litespeed cache · CWE-79 | Средняя5,4 | — | 16,8 % | 11 янв. 2024 г. |
26Наблюдать | CVE-2018-19791Эксплойта нет | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to ampliflitespeedtech · openlitespeed · CWE-20 | Средняя6,5 | — | 1,2 % | 3 дек. 2018 г. |
26Наблюдать | CVE-2018-19792Эксплойта нет | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unlitespeedtech · openlitespeed · CWE-119 | Средняя6,7 | — | 0,4 % | 3 дек. 2018 г. |
24Наблюдать | CVE-2024-47374Proof of concept | WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Средняя6,1 | — | 1,4 % | 5 окт. 2024 г. |
24Наблюдать | CVE-2021-24964Эксплойта нет | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSSlitespeedtech · litespeed cache · CWE-79 | Средняя6,1 | — | 1,2 % | 3 янв. 2022 г. |
24Наблюдать | CVE-2020-29172Эксплойта нет | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP settilitespeedtech · litespeed cache · CWE-79 | Средняя6,1 | — | 0,9 % | 25 дек. 2020 г. |
- CVE-2026-4817270На этой неделе
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %litespeedtech · litespeed cpanel plugin20 мая 2026 г.
- CVE-2024-4400064На этой неделе
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %litespeedtech · litespeed cache20 окт. 2024 г.
- CVE-2026-5442064На этой неделе
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP
ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 1 %litespeedtech · litespeed cpanel plugin14 июн. 2026 г.
- CVE-2024-2800059В плане
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 68 %litespeedtech · litespeed cache21 авг. 2024 г.
- CVE-2023-4000040В плане
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
СредняяCVSS 6,1Proof of conceptEPSS 55 %litespeedtech · litespeed cache16 апр. 2024 г.
- CVE-2022-3059240В плане
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %litespeedtech · lsquic11 мая 2022 г.
- CVE-2020-551939Наблюдать
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %litespeedtech · openlitespeed6 янв. 2020 г.
- CVE-2024-5055039Наблюдать
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %litespeedtech · litespeed cache29 окт. 2024 г.
- CVE-2024-2567839Наблюдать
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %litespeedtech · lsquic9 февр. 2024 г.
- CVE-2010-233338Наблюдать
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque
СредняяCVSS 5,0Готовый эксплойтEPSS 60 %litespeedtech · litespeed web server18 июн. 2010 г.
- CVE-2022-007338Наблюдать
Authenticated Remote Code Execution in OpenLiteSpeed Web Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %litespeedtech · openlitespeed27 окт. 2022 г.
- CVE-2021-2675836Наблюдать
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %litespeedtech · openlitespeed7 апр. 2021 г.
- CVE-2026-3138635Наблюдать
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %litespeedtech · litespeed web server16 мар. 2026 г.
- CVE-2022-007435Наблюдать
Privilege Escalation in OpenLiteSpeed Web Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %litespeedtech · openlitespeed27 окт. 2022 г.
- CVE-2024-4763735Наблюдать
WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %litespeedtech · litespeed cache16 окт. 2024 г.
- CVE-2022-4680035Наблюдать
WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %litespeedtech · litespeed cache25 мая 2023 г.
- CVE-2015-389030Наблюдать
Use-after-free vulnerability in Open Litespeed before 1.3.10.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %litespeedtech · openlitespeed20 сент. 2017 г.
- CVE-2025-5493930Наблюдать
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %litespeedtech · litespeed web adc1 авг. 2025 г.
- CVE-2023-4051830Наблюдать
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %litespeedtech · openlitespeed14 авг. 2023 г.
- CVE-2023-437226Наблюдать
LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 17 %litespeedtech · litespeed cache11 янв. 2024 г.
- CVE-2018-1979126Наблюдать
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif
СредняяCVSS 6,5Эксплойта нетEPSS 1 %litespeedtech · openlitespeed3 дек. 2018 г.
- CVE-2018-1979226Наблюдать
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un
СредняяCVSS 6,7Эксплойта нетEPSS 0 %litespeedtech · openlitespeed3 дек. 2018 г.
- CVE-2024-4737424Наблюдать
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Proof of conceptEPSS 1 %litespeedtech · litespeed cache5 окт. 2024 г.
- CVE-2021-2496424Наблюдать
LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS
СредняяCVSS 6,1Эксплойта нетEPSS 1 %litespeedtech · litespeed cache3 янв. 2022 г.
- CVE-2020-2917224Наблюдать
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti
СредняяCVSS 6,1Эксплойта нетEPSS 1 %litespeedtech · litespeed cache25 дек. 2020 г.