Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Litespeedtech

First CVE: Nov 23, 2004Active for: 22 yearsTotal CVEs: 39
66.1
VTI Score
TOP TARGET

Litespeedtech maintains a focused but prominently deployed portfolio of web-server, caching, and load-balancing products including LiteSpeed Web Server, OpenLiteSpeed, LiteSpeed Cache, and related infrastructure components. Despite a narrow product count, these offerings occupy a significant position in web-serving and content-acceleration layers, where vulnerabilities skew toward serious outcomes and frequently acquire public exploit code. The exposure recurs through application-layer and access-control weakness classes including cross-site scripting, improper input validation, privilege assignment flaws, resource-exhaustion conditions, and cross-site request forgery, reflecting the parsing and session-management demands of web-facing middleware. The vendor's disclosures also demonstrate a moderate tendency toward confirmed in-the-wild exploitation, indicating that flaws in this tier attract active attention. Defenders should prioritize patches for internet-reachable LiteSpeed installations and monitor this vendor's releases closely; current exploitation activity, severity, and exposure figures are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
5.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Litespeedtech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Jun 14, 2026
40 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-44000CRITICAL
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n
Oct 20, 20249.892NOYES
CVE-2026-48172CRITICAL
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of gre
May 21, 20269.888YESNO
CVE-2024-28000CRITICAL
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
Aug 21, 20249.884NOYES
CVE-2026-54420HIGH
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting
Jun 14, 20268.579YESNO
CVE-2010-2333MEDIUM
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt f
Jun 18, 20105.066NOYES
CVE-2023-40000MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects Li
Apr 16, 20246.163NOYES
CVE-2024-47374MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This
Oct 5, 20246.133NOYES
CVE-2022-0073HIGH
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 version
Oct 27, 20228.833NONO
CVE-2024-50550CRITICAL
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a thro
Oct 29, 20249.831NONO
CVE-2022-0074HIGH
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.
Oct 27, 20228.830NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
54%
28%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.6%)
Network35 (89.7%)
Unknown3 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (89.7%)
High1 (2.6%)
Unknown3 (7.7%)
User Interaction
None24 (61.5%)
Unknown3 (7.7%)
Required12 (30.8%)
Privileges Required
Low10 (25.6%)
High4 (10.3%)
None22 (56.4%)
Unknown3 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
2 CVEs
5.1% of CVEs· 99th percentile
Metasploit
2 CVEs
5.1% of CVEs· 98th percentile
Nuclei
4 CVEs
10.3% of CVEs· 96th percentile
ExploitDB
4 CVEs
10.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Litespeedtech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Litespeedtech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Litespeedtech's Products

View all 6 CNAs →

Top CWEs