Litespeed Web Server
Vendor:
First CVE: Nov 23, 2004 · Active for 21 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Litespeed Web Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Mar 16, 2026
130 days ago
CVE Severity & Scoring
Litespeed Web Server5 CVEs
60%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (40.0%)
Unknown3 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (40.0%)
High0 (0.0%)
Unknown3 (60.0%)
User Interaction
None2 (40.0%)
Unknown3 (60.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (20.0%)
None1 (20.0%)
Unknown3 (60.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2333MEDIUM LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt f | Jun 18, 2010 | 5.0 | 66 | NO | YES |
CVE-2025-54939HIGH LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | Aug 1, 2025 | 7.5 | 28 | NO | NO |
CVE-2026-31386HIGH OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the | Mar 16, 2026 | 7.2 | 27 | NO | NO |
CVE-2012-4871MEDIUM Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script | Sep 6, 2012 | 4.3 | 24 | NO | YES |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
20.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
40.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Litespeed Web Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.11 | 1 | 4.3 | 1.6% | 0 | 1 |
| 4.0.9 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.8 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.7 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.6 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.5 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.4 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.3 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.2 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.14 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.13 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.12 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.11 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.10 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0.1 | 1 | 5.0 | 60.2% | 0 | 1 |
| 4.0 | 1 | 5.0 | 60.2% | 0 | 1 |
| 1.0.1 | 1 | 5.0 | 10.4% | 0 | 0 |