Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Litespeed Cpanel Plugin HIGH 8.5
CVE-2026-54420 KEV

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s…

Fix: 2.4.8 / 5.3.2.0+
Fix from $1,950 2026-06-14
Litespeed Cpanel Plugin CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…

Fix: 2.4.7 / 5.3.1.0+
Fix from $2,300 2026-05-21
Litespeed Web Server HIGH 7.2
CVE-2026-31386

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex…

Fix: 6.3.5+
Fix from $1,950 2026-03-16
Litespeed Web Adc HIGH 7.5
CVE-2025-54939

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

Fix: 1.8.4 / 3.3.1+
Fix from $1,950 2025-08-01
Litespeed Cache CRITICAL 9.8
CVE-2024-50550

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects…

Fix: 6.5.2+
Fix from $2,300 2024-10-29
Litespeed Cache CRITICAL 9.8
CVE-2024-44000EPSS 82%

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue …

Fix: 6.5.0.1+
Fix from $2,300 2024-10-20
Litespeed Cache HIGH 8.8
CVE-2024-47637

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca…

Fix: 6.5.1+
Fix from $1,950 2024-10-16
Litespeed Cache MEDIUM 6.1
CVE-2024-47374

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee…

Fix: 6.5.1+
Fix from $1,600 2024-10-05
Litespeed Cache MEDIUM 5.4
CVE-2024-47373

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespee…

Fix: 6.5.1+
Fix from $1,600 2024-10-05
Litespeed Cache CRITICAL 9.8
CVE-2024-28000EPSS 68%

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a t…

Fix: 6.4+
Fix from $2,300 2024-08-21
Litespeed Cache MEDIUM 5.4
CVE-2024-3246

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to mi…

Fix: 6.3+
Fix from $1,600 2024-07-24
Openlitespeed MEDIUM 5.3
CVE-2024-31617

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

Fix: 1.8.1+
Fix from $1,600 2024-05-22
Litespeed Cache MEDIUM 6.1
CVE-2023-40000EPSS 55%

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows S…

Fix: 5.7.0.1+
Fix from $1,600 2024-04-16
Litespeed Cache MEDIUM 5.3
CVE-2023-45000

Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.

Fix: 5.7.0.1+
Fix from $1,600 2024-04-16
Lsquic CRITICAL 9.8
CVE-2024-25678

In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

Fix: 4.0.4+
Fix from $2,300 2024-02-09
Litespeed Cache MEDIUM 5.4
CVE-2023-4372EPSS 20%

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 d…

Fix: after 5.6
Fix from $1,600 2024-01-11
Openlitespeed HIGH 7.5
CVE-2023-40518

LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

Fix: 1.7.18+
Fix from $1,950 2023-08-14
Litespeed Cache HIGH 8.8
CVE-2022-46800

Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.

Fix: after 5.3
Fix from $1,950 2023-05-25
Openlitespeed HIGH 8.8
CVE-2022-0073EPSS 9%

Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injecti…

Fix: after 1.7.16.1
Fix from $1,950 2022-10-27
Openlitespeed HIGH 8.8
CVE-2022-0074

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation…

Fix: 1.7.16.1+
Fix from $1,950 2022-10-27
Openlitespeed MEDIUM 5.8
CVE-2022-0072

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This …

Fix: 1.7.16.1+
Fix from $1,600 2022-10-27
Lsquic CRITICAL 9.8
CVE-2022-30592

liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

Fix: 3.1.0+
Fix from $2,300 2022-05-11
Litespeed Cache MEDIUM 6.1
CVE-2021-24964

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to ma…

Fix: 4.4.4+
Fix from $1,600 2022-01-03
Openlitespeed HIGH 8.8
CVE-2021-26758

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute comma…

No fix yet
Fix from $1,950 2021-04-07
Litespeed Cache MEDIUM 6.1
CVE-2020-29172

A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.

Fix: 3.6.1+
Fix from $1,600 2020-12-26
Openlitespeed CRITICAL 9.8
CVE-2020-5519

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App…

Fix: 1.6.5+
Fix from $2,300 2020-01-06
Openlitespeed MEDIUM 6.7
CVE-2018-19792

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified…

Fix: after 1.4.41
Fix from $1,600 2018-12-03
Openlitespeed MEDIUM 6.5
CVE-2018-19791

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the res…

Fix: 1.5.0+
Fix from $1,600 2018-12-03
Openlitespeed HIGH 7.5
CVE-2015-3890

Use-after-free vulnerability in Open Litespeed before 1.3.10.

Fix: 1.3.10+
Fix from $1,950 2017-09-20
Litespeed Web Server MEDIUM 5.0
CVE-2010-2333EPSS 60%

LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a…

Patch available
Fix from $1,600 2010-06-18