Litespeedtech maintains a focused but prominently deployed portfolio of web-server, caching, and load-balancing products including LiteSpeed Web Server, OpenLiteSpeed, LiteSpeed Cache, and related infrastructure components. Despite a narrow product count, these offerings occupy a significant position in web-serving and content-acceleration layers, where vulnerabilities skew toward serious outcomes and frequently acquire public exploit code. The exposure recurs through application-layer and access-control weakness classes including cross-site scripting, improper input validation, privilege assignment flaws, resource-exhaustion conditions, and cross-site request forgery, reflecting the parsing and session-management demands of web-facing middleware. The vendor's disclosures also demonstrate a moderate tendency toward confirmed in-the-wild exploitation, indicating that flaws in this tier attract active attention. Defenders should prioritize patches for internet-reachable LiteSpeed installations and monitor this vendor's releases closely; current exploitation activity, severity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Litespeedtech over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-44000CRITICAL Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n | Oct 20, 2024 | 9.8 | 92 | NO | YES |
CVE-2026-48172CRITICAL LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of gre | May 21, 2026 | 9.8 | 88 | YES | NO |
CVE-2024-28000CRITICAL Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | Aug 21, 2024 | 9.8 | 84 | NO | YES |
CVE-2026-54420HIGH LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting | Jun 14, 2026 | 8.5 | 79 | YES | NO |
CVE-2010-2333MEDIUM LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt f | Jun 18, 2010 | 5.0 | 66 | NO | YES |
CVE-2023-40000MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects Li | Apr 16, 2024 | 6.1 | 63 | NO | YES |
CVE-2024-47374MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This | Oct 5, 2024 | 6.1 | 33 | NO | YES |
CVE-2022-0073HIGH Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 version | Oct 27, 2022 | 8.8 | 33 | NO | NO |
CVE-2024-50550CRITICAL Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a thro | Oct 29, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-0074HIGH Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1. | Oct 27, 2022 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Litespeedtech.
Media articles that mention a CVE ID that affects a product developed by Litespeedtech — matched by CVE ID, not by vendor name.