Litespeed-technologies
8 CVEs tracked since 2022. Since Oct 2022, none of them reached CISA KEV.
Litespeed-technologies CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-10 | 3 | 0 |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | 5 | 0 |
Products
The products that kept showing up in Litespeed-technologies's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Litespeed-technologies.
- CVE-2026-84761WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) vulnerability7.2
- CVE-2026-54420LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running C...8.5
- CVE-2026-48172LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jso...9.8
- CVE-2026-31386OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative pr...7.2
- CVE-2024-51915WordPress LiteSpeed Cache plugin <= 6.5.2 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2021-47855Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting7.2
- CVE-2025-47437WordPress LiteSpeed Cache plugin <= 7.0.1 - Server Side Request Forgery (SSRF) vulnerability6.4
- CVE-2024-50550WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability8.1
- CVE-2024-44000WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability9.8
- CVE-2024-47637WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability8.8
- CVE-2024-47373WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2024-47374WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2024-28000WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability9.8
- CVE-2023-45000WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Broken Access Control on API vulnerability8.2
- CVE-2023-40000WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability8.3
The record
- Peak rank
- #145 in Oct 2024
- Busiest month shown
- Oct 2024, 5 CVEs
- Months with a KEV entry
- 0 since Oct 2022
- Monthly snapshots
- 2 since 2022