Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-54420 KEV
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s…
Litespeed Cpanel Plugin
2.4.8 / 5.3.2.0+
CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…
Litespeed Cpanel Plugin
2.4.7 / 5.3.1.0+
HIGH 7.2
CVE-2026-31386
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex…
Litespeed Web Server
6.3.5+
HIGH 7.5
CVE-2025-54939
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Litespeed Web Adc
1.8.4 / 3.3.1+
CRITICAL 9.8
CVE-2024-50550
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects…
Litespeed Cache
6.5.2+
CRITICAL 9.8
CVE-2024-44000EPSS 82%
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue …
Litespeed Cache
6.5.0.1+
HIGH 8.8
CVE-2024-47637
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca…
Litespeed Cache
6.5.1+
MEDIUM 6.1
CVE-2024-47374
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee…
Litespeed Cache
6.5.1+
MEDIUM 5.4
CVE-2024-47373
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee…
Litespeed Cache
6.5.1+
CRITICAL 9.8
CVE-2024-28000EPSS 68%
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a t…
Litespeed Cache
6.4+
MEDIUM 5.4
CVE-2024-3246
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to mi…
Litespeed Cache
6.3+
MEDIUM 5.3
CVE-2024-31617
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Openlitespeed
1.8.1+
MEDIUM 6.1
CVE-2023-40000EPSS 55%
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows S…
Litespeed Cache
5.7.0.1+
MEDIUM 5.3
CVE-2023-45000
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.
Litespeed Cache
5.7.0.1+
CRITICAL 9.8
CVE-2024-25678
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
Lsquic
4.0.4+
MEDIUM 5.4
CVE-2023-4372EPSS 20%
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 d…
Litespeed Cache
after 5.6
HIGH 7.5
CVE-2023-40518
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
Openlitespeed
1.7.18+
HIGH 8.8
CVE-2022-46800
Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.
Litespeed Cache
after 5.3
HIGH 8.8
CVE-2022-0073EPSS 9%
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injecti…
Openlitespeed
after 1.7.16.1
HIGH 8.8
CVE-2022-0074
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation…
Openlitespeed
1.7.16.1+
MEDIUM 5.8
CVE-2022-0072
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This …
Openlitespeed
1.7.16.1+
CRITICAL 9.8
CVE-2022-30592
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
Lsquic
3.1.0+
MEDIUM 6.1
CVE-2021-24964
The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to ma…
Litespeed Cache
4.4.4+
HIGH 8.8
CVE-2021-26758
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute comma…
Openlitespeed
No fix yet
MEDIUM 6.1
CVE-2020-29172
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
Litespeed Cache
3.6.1+
CRITICAL 9.8
CVE-2020-5519
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App…
Openlitespeed
1.6.5+
MEDIUM 6.7
CVE-2018-19792
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified…
Openlitespeed
after 1.4.41
MEDIUM 6.5
CVE-2018-19791
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the res…
Openlitespeed
1.5.0+
HIGH 7.5
CVE-2015-3890
Use-after-free vulnerability in Open Litespeed before 1.3.10.
Openlitespeed
1.3.10+
MEDIUM 5.0
CVE-2010-2333EPSS 60%
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a…
Litespeed Web Server
Patch available