litespeedtech kayıtları
litespeedtech üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %5,9
- Silahlaştırılmış
- 4 · %11,8
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %32,4
- Yayından KEV’e ortanca
- 4 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-266 Incorrect Privilege Assignment3
- CWE-20 Improper Input Validation3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-23 Relative Path Traversal1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
70Bu hafta | CVE-2026-48172Silahlaştırılmış | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.litespeedtech · litespeed cpanel plugin · CWE-266 | Kritik10,0 | KEV | %1,0 | 20 May 2026 |
64Bu hafta | CVE-2024-44000Silahlaştırılmış | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Kritik9,8 | — | %82,3 | 20 Eki 2024 |
64Bu hafta | CVE-2026-54420Silahlaştırılmış | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPlitespeedtech · litespeed cpanel plugin · CWE-61 | Yüksek8,5 | KEV | %0,8 | 14 Haz 2026 |
59Planlayın | CVE-2024-28000Kavram kanıtı | WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Kritik9,8 | — | %68,3 | 21 Ağu 2024 |
40Planlayın | CVE-2023-40000Kavram kanıtı | WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Orta6,1 | — | %54,9 | 16 Nis 2024 |
40Planlayın | CVE-2022-30592Kavram kanıtı | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.litespeedtech · lsquic · CWE-476 | Kritik9,8 | — | %3,2 | 11 May 2022 |
39İzleyin | CVE-2020-5519İstismar yok | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Extlitespeedtech · openlitespeed · CWE-20 | Kritik9,8 | — | %1,2 | 6 Oca 2020 |
39İzleyin | CVE-2024-50550İstismar yok | WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Kritik9,8 | — | %0,9 | 29 Eki 2024 |
39İzleyin | CVE-2024-25678İstismar yok | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.litespeedtech · lsquic · CWE-354 | Kritik9,8 | — | %0,4 | 9 Şub 2024 |
38İzleyin | CVE-2010-2333Silahlaştırılmış | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP requelitespeedtech · litespeed web server · CWE-200 | Orta5,0 | — | %60,2 | 18 Haz 2010 |
38İzleyin | CVE-2022-0073İstismar yok | Authenticated Remote Code Execution in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-20 | Yüksek8,8 | — | %8,8 | 27 Eki 2022 |
36İzleyin | CVE-2021-26758İstismar yok | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execlitespeedtech · openlitespeed · CWE-269 | Yüksek8,8 | — | %2,7 | 7 Nis 2021 |
35İzleyin | CVE-2026-31386İstismar yok | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.litespeedtech · litespeed web server · CWE-78 | Yüksek8,6 | — | %2,1 | 16 Mar 2026 |
35İzleyin | CVE-2022-0074İstismar yok | Privilege Escalation in OpenLiteSpeed Web Serverlitespeedtech · openlitespeed · CWE-426 | Yüksek8,8 | — | %1,2 | 27 Eki 2022 |
35İzleyin | CVE-2024-47637İstismar yok | WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerabilitylitespeedtech · litespeed cache · CWE-23 | Yüksek8,8 | — | %0,6 | 16 Eki 2024 |
35İzleyin | CVE-2022-46800İstismar yok | WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)litespeedtech · litespeed cache · CWE-352 | Yüksek8,8 | — | %0,3 | 25 May 2023 |
30İzleyin | CVE-2015-3890İstismar yok | Use-after-free vulnerability in Open Litespeed before 1.3.10.litespeedtech · openlitespeed · CWE-416 | Yüksek7,5 | — | %1,1 | 20 Eyl 2017 |
30İzleyin | CVE-2025-54939Kavram kanıtı | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.litespeedtech · litespeed web adc · CWE-770 | Yüksek7,5 | — | %0,8 | 1 Ağu 2025 |
30İzleyin | CVE-2023-40518İstismar yok | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.litespeedtech · openlitespeed | Yüksek7,5 | — | %0,7 | 14 Ağu 2023 |
26İzleyin | CVE-2023-4372İstismar yok | LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodelitespeedtech · litespeed cache · CWE-79 | Orta5,4 | — | %16,8 | 11 Oca 2024 |
26İzleyin | CVE-2018-19791İstismar yok | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to ampliflitespeedtech · openlitespeed · CWE-20 | Orta6,5 | — | %1,2 | 3 Ara 2018 |
26İzleyin | CVE-2018-19792İstismar yok | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unlitespeedtech · openlitespeed · CWE-119 | Orta6,7 | — | %0,4 | 3 Ara 2018 |
24İzleyin | CVE-2024-47374Kavram kanıtı | WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerabilitylitespeedtech · litespeed cache · CWE-79 | Orta6,1 | — | %1,4 | 5 Eki 2024 |
24İzleyin | CVE-2021-24964İstismar yok | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSSlitespeedtech · litespeed cache · CWE-79 | Orta6,1 | — | %1,2 | 3 Oca 2022 |
24İzleyin | CVE-2020-29172İstismar yok | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP settilitespeedtech · litespeed cache · CWE-79 | Orta6,1 | — | %0,9 | 25 Ara 2020 |
- CVE-2026-4817270Bu hafta
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1litespeedtech · litespeed cpanel plugin20 May 2026
- CVE-2024-4400064Bu hafta
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %82litespeedtech · litespeed cache20 Eki 2024
- CVE-2026-5442064Bu hafta
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP
YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %1litespeedtech · litespeed cpanel plugin14 Haz 2026
- CVE-2024-2800059Planlayın
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %68litespeedtech · litespeed cache21 Ağu 2024
- CVE-2023-4000040Planlayın
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
OrtaCVSS 6,1Kavram kanıtıEPSS %55litespeedtech · litespeed cache16 Nis 2024
- CVE-2022-3059240Planlayın
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
KritikCVSS 9,8Kavram kanıtıEPSS %3litespeedtech · lsquic11 May 2022
- CVE-2020-551939İzleyin
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext
KritikCVSS 9,8İstismar yokEPSS %1litespeedtech · openlitespeed6 Oca 2020
- CVE-2024-5055039İzleyin
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
KritikCVSS 9,8İstismar yokEPSS %1litespeedtech · litespeed cache29 Eki 2024
- CVE-2024-2567839İzleyin
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
KritikCVSS 9,8İstismar yokEPSS %0litespeedtech · lsquic9 Şub 2024
- CVE-2010-233338İzleyin
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque
OrtaCVSS 5,0SilahlaştırılmışEPSS %60litespeedtech · litespeed web server18 Haz 2010
- CVE-2022-007338İzleyin
Authenticated Remote Code Execution in OpenLiteSpeed Web Server
YüksekCVSS 8,8İstismar yokEPSS %9litespeedtech · openlitespeed27 Eki 2022
- CVE-2021-2675836İzleyin
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec
YüksekCVSS 8,8İstismar yokEPSS %3litespeedtech · openlitespeed7 Nis 2021
- CVE-2026-3138635İzleyin
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.
YüksekCVSS 8,6İstismar yokEPSS %2litespeedtech · litespeed web server16 Mar 2026
- CVE-2022-007435İzleyin
Privilege Escalation in OpenLiteSpeed Web Server
YüksekCVSS 8,8İstismar yokEPSS %1litespeedtech · openlitespeed27 Eki 2022
- CVE-2024-4763735İzleyin
WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1litespeedtech · litespeed cache16 Eki 2024
- CVE-2022-4680035İzleyin
WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0litespeedtech · litespeed cache25 May 2023
- CVE-2015-389030İzleyin
Use-after-free vulnerability in Open Litespeed before 1.3.10.
YüksekCVSS 7,5İstismar yokEPSS %1litespeedtech · openlitespeed20 Eyl 2017
- CVE-2025-5493930İzleyin
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
YüksekCVSS 7,5Kavram kanıtıEPSS %1litespeedtech · litespeed web adc1 Ağu 2025
- CVE-2023-4051830İzleyin
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
YüksekCVSS 7,5İstismar yokEPSS %1litespeedtech · openlitespeed14 Ağu 2023
- CVE-2023-437226İzleyin
LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %17litespeedtech · litespeed cache11 Oca 2024
- CVE-2018-1979126İzleyin
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif
OrtaCVSS 6,5İstismar yokEPSS %1litespeedtech · openlitespeed3 Ara 2018
- CVE-2018-1979226İzleyin
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un
OrtaCVSS 6,7İstismar yokEPSS %0litespeedtech · openlitespeed3 Ara 2018
- CVE-2024-4737424İzleyin
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1Kavram kanıtıEPSS %1litespeedtech · litespeed cache5 Eki 2024
- CVE-2021-2496424İzleyin
LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %1litespeedtech · litespeed cache3 Oca 2022
- CVE-2020-2917224İzleyin
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti
OrtaCVSS 6,1İstismar yokEPSS %1litespeedtech · litespeed cache25 Ara 2020