Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.5 CVE-2026-54420 KEV LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s… Litespeed Cpanel Plugin 2.4.8 / 5.3.2.0+ Fix from $1,9502026-06-14 CRITICAL 9.8 CVE-2026-48172 KEVEPSS 19% LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… Litespeed Cpanel Plugin 2.4.7 / 5.3.1.0+ Fix from $2,3002026-05-21 HIGH 7.2 CVE-2026-31386 OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex… Litespeed Web Server 6.3.5+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2025-54939 LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. Litespeed Web Adc 1.8.4 / 3.3.1+ Fix from $1,9502025-08-01 CRITICAL 9.8 CVE-2024-50550 Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects… Litespeed Cache 6.5.2+ Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-44000EPSS 82% Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue … Litespeed Cache 6.5.0.1+ Fix from $2,3002024-10-20 HIGH 8.8 CVE-2024-47637 Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca… Litespeed Cache 6.5.1+ Fix from $1,9502024-10-16 MEDIUM 6.1 CVE-2024-47374 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee… Litespeed Cache 6.5.1+ Fix from $1,6002024-10-05 MEDIUM 5.4 CVE-2024-47373 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee… Litespeed Cache 6.5.1+ Fix from $1,6002024-10-05 CRITICAL 9.8 CVE-2024-28000EPSS 68% Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a t… Litespeed Cache 6.4+ Fix from $2,3002024-08-21 MEDIUM 5.4 CVE-2024-3246 The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to mi… Litespeed Cache 6.3+ Fix from $1,6002024-07-24 MEDIUM 5.3 CVE-2024-31617 OpenLiteSpeed before 1.8.1 mishandles chunked encoding. Openlitespeed 1.8.1+ Fix from $1,6002024-05-22 MEDIUM 6.1 CVE-2023-40000EPSS 55% Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows S… Litespeed Cache 5.7.0.1+ Fix from $1,6002024-04-16 MEDIUM 5.3 CVE-2023-45000 Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7. Litespeed Cache 5.7.0.1+ Fix from $1,6002024-04-16 CRITICAL 9.8 CVE-2024-25678 In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled. Lsquic 4.0.4+ Fix from $2,3002024-02-09 MEDIUM 5.4 CVE-2023-4372EPSS 20% The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 d… Litespeed Cache after 5.6 Fix from $1,6002024-01-11 HIGH 7.5 CVE-2023-40518 LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers. Openlitespeed 1.7.18+ Fix from $1,9502023-08-14 HIGH 8.8 CVE-2022-46800 Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions. Litespeed Cache after 5.3 Fix from $1,9502023-05-25 HIGH 8.8 CVE-2022-0073EPSS 9% Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injecti… Openlitespeed after 1.7.16.1 Fix from $1,9502022-10-27 HIGH 8.8 CVE-2022-0074 Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation… Openlitespeed 1.7.16.1+ Fix from $1,9502022-10-27 MEDIUM 5.8 CVE-2022-0072 Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This … Openlitespeed 1.7.16.1+ Fix from $1,6002022-10-27 CRITICAL 9.8 CVE-2022-30592 liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. Lsquic 3.1.0+ Fix from $2,3002022-05-11 MEDIUM 6.1 CVE-2021-24964 The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to ma… Litespeed Cache 4.4.4+ Fix from $1,6002022-01-03 HIGH 8.8 CVE-2021-26758 Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute comma… Openlitespeed No fix yet Fix from $1,9502021-04-07 MEDIUM 6.1 CVE-2020-29172 A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting. Litespeed Cache 3.6.1+ Fix from $1,6002020-12-26 CRITICAL 9.8 CVE-2020-5519 The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App… Openlitespeed 1.6.5+ Fix from $2,3002020-01-06 MEDIUM 6.7 CVE-2018-19792 The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified… Openlitespeed after 1.4.41 Fix from $1,6002018-12-03 MEDIUM 6.5 CVE-2018-19791 The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the res… Openlitespeed 1.5.0+ Fix from $1,6002018-12-03 HIGH 7.5 CVE-2015-3890 Use-after-free vulnerability in Open Litespeed before 1.3.10. Openlitespeed 1.3.10+ Fix from $1,9502017-09-20 MEDIUM 5.0 CVE-2010-2333EPSS 60% LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a… Litespeed Web Server Patch available Fix from $1,6002010-06-18