Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LiteSpeed Technologies — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting LiteSpeed Technologies. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LiteSpeed Technologies develops high-performance web server and caching solutions primarily used to enhance website speed and efficiency. Historically, its products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and improper access controls. While no major public security incidents have been widely documented, the 16 CVEs on record highlight recurring issues in request handling and authentication mechanisms. The company typically addresses vulnerabilities through timely patches, though the persistence of certain classes of flaws suggests ongoing challenges in secure coding practices for its web server components.

CVE ID Title CVSS Severity Published
CVE-2026-84761 WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) vulnerability — LiteSpeed Cache CWE-918 7.2 High 2026-09-03
CVE-2026-54420 LiteSpeed cPanel Plugin 后置链接漏洞 — cPanel Plugin CWE-61 8.5 High 2026-06-14
CVE-2026-48172 LiteSpeed User-End cPanel Plugin 安全漏洞 — cPanel Plugin CWE-266 - - 2026-05-21
CVE-2026-31386 LiteSpeed Web Server Enterprise和LiteSpeed OpenLiteSpeed 操作系统命令注入漏洞 — OpenLiteSpeed CWE-78 7.2AI High AI 2026-03-16
CVE-2024-51915 WordPress LiteSpeed Cache plugin <= 6.5.2 - Cross Site Scripting (XSS) vulnerability — LiteSpeed Cache CWE-79 6.5 Medium 2026-02-20
CVE-2021-47855 Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting — OpenLiteSpeed CWE-79 7.2 High 2026-01-21
CVE-2025-47437 WordPress LiteSpeed Cache plugin <= 7.0.1 - Server Side Request Forgery (SSRF) vulnerability — LiteSpeed Cache CWE-918 6.4 Medium 2025-09-09
CVE-2024-50550 WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability — LiteSpeed Cache CWE-266 8.1 High 2024-10-29
CVE-2024-44000 WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability — LiteSpeed Cache CWE-522 9.8 Critical 2024-10-20
CVE-2024-47637 WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability — LiteSpeed Cache CWE-23 8.8 High 2024-10-16
CVE-2024-47373 WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability — LiteSpeed Cache CWE-79 6.5 Medium 2024-10-05
CVE-2024-47374 WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability — LiteSpeed Cache CWE-79 7.1 High 2024-10-05
CVE-2024-28000 WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability — LiteSpeed Cache CWE-266 9.8 Critical 2024-08-21
CVE-2023-45000 WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Broken Access Control on API vulnerability — LiteSpeed Cache CWE-862 8.2 High 2024-04-16
CVE-2023-40000 WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability — LiteSpeed Cache CWE-79 8.3 High 2024-04-16
CVE-2022-46800 WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF) — LiteSpeed Cache CWE-352 5.4 Medium 2023-05-25
CVE-2022-0074 Privilege Escalation in OpenLiteSpeed Web Server — OpenLiteSpeed Web Server CWE-426 8.8 High 2022-10-27
CVE-2022-0073 Authenticated Remote Code Execution in OpenLiteSpeed Web Server — OpenLiteSpeed Web Server CWE-20 8.8 High 2022-10-27
CVE-2022-0072 Directory Traversal in OpenLiteSpeed Web Server — OpenLiteSpeed Web Server CWE-22 5.8 Medium 2022-10-27

This page lists every published CVE security advisory associated with LiteSpeed Technologies. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.