İçeriğe atla
Noroxi

litespeedtech kayıtları

litespeedtech üreticisine ait 34 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %5,9
Silahlaştırılmış
4 · %11,8
Pre-auth RCE
0
Düzeltme kaydı olan
%32,4
Yayından KEV’e ortanca
4 gün

Tüm kayıtlar

34 kayıt
  • CVE-2026-48172
    70Bu hafta

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1

    litespeedtech · litespeed cpanel plugin20 May 2026

  • CVE-2024-44000
    64Bu hafta

    WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability

    KritikCVSS 9,8SilahlaştırılmışEPSS %82

    litespeedtech · litespeed cache20 Eki 2024

  • CVE-2026-54420
    64Bu hafta

    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP

    YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %1

    litespeedtech · litespeed cpanel plugin14 Haz 2026

  • CVE-2024-28000
    59Planlayın

    WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    litespeedtech · litespeed cache21 Ağu 2024

  • CVE-2023-40000
    40Planlayın

    WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability

    OrtaCVSS 6,1Kavram kanıtıEPSS %55

    litespeedtech · litespeed cache16 Nis 2024

  • CVE-2022-30592
    40Planlayın

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    litespeedtech · lsquic11 May 2022

  • CVE-2020-5519
    39İzleyin

    The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > Ext

    KritikCVSS 9,8İstismar yokEPSS %1

    litespeedtech · openlitespeed6 Oca 2020

  • CVE-2024-50550
    39İzleyin

    WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    litespeedtech · litespeed cache29 Eki 2024

  • CVE-2024-25678
    39İzleyin

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

    KritikCVSS 9,8İstismar yokEPSS %0

    litespeedtech · lsquic9 Şub 2024

  • CVE-2010-2333
    38İzleyin

    LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP reque

    OrtaCVSS 5,0SilahlaştırılmışEPSS %60

    litespeedtech · litespeed web server18 Haz 2010

  • CVE-2022-0073
    38İzleyin

    Authenticated Remote Code Execution in OpenLiteSpeed Web Server

    YüksekCVSS 8,8İstismar yokEPSS %9

    litespeedtech · openlitespeed27 Eki 2022

  • CVE-2021-26758
    36İzleyin

    Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and exec

    YüksekCVSS 8,8İstismar yokEPSS %3

    litespeedtech · openlitespeed7 Nis 2021

  • CVE-2026-31386
    35İzleyin

    OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability.

    YüksekCVSS 8,6İstismar yokEPSS %2

    litespeedtech · litespeed web server16 Mar 2026

  • CVE-2022-0074
    35İzleyin

    Privilege Escalation in OpenLiteSpeed Web Server

    YüksekCVSS 8,8İstismar yokEPSS %1

    litespeedtech · openlitespeed27 Eki 2022

  • CVE-2024-47637
    35İzleyin

    WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    litespeedtech · litespeed cache16 Eki 2024

  • CVE-2022-46800
    35İzleyin

    WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    litespeedtech · litespeed cache25 May 2023

  • CVE-2015-3890
    30İzleyin

    Use-after-free vulnerability in Open Litespeed before 1.3.10.

    YüksekCVSS 7,5İstismar yokEPSS %1

    litespeedtech · openlitespeed20 Eyl 2017

  • CVE-2025-54939
    30İzleyin

    LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    litespeedtech · litespeed web adc1 Ağu 2025

  • CVE-2023-40518
    30İzleyin

    LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

    YüksekCVSS 7,5İstismar yokEPSS %1

    litespeedtech · openlitespeed14 Ağu 2023

  • CVE-2023-4372
    26İzleyin

    LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %17

    litespeedtech · litespeed cache11 Oca 2024

  • CVE-2018-19791
    26İzleyin

    The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplif

    OrtaCVSS 6,5İstismar yokEPSS %1

    litespeedtech · openlitespeed3 Ara 2018

  • CVE-2018-19792
    26İzleyin

    The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have un

    OrtaCVSS 6,7İstismar yokEPSS %0

    litespeedtech · openlitespeed3 Ara 2018

  • CVE-2024-47374
    24İzleyin

    WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    litespeedtech · litespeed cache5 Eki 2024

  • CVE-2021-24964
    24İzleyin

    LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS

    OrtaCVSS 6,1İstismar yokEPSS %1

    litespeedtech · litespeed cache3 Oca 2022

  • CVE-2020-29172
    24İzleyin

    A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setti

    OrtaCVSS 6,1İstismar yokEPSS %1

    litespeedtech · litespeed cache25 Ara 2020