Litespeedtech
Litespeedtech Litespeed Cache: vulnerabilidades y CVE
Litespeedtech Litespeed Cache tiene 21 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76579 | Media (4.7) | 0.38% | — | 19 sept 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This… |
| CVE-2026-84761 | Alta (7.2) | 0.27% | — | 3 sept 2026 | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. |
| CVE-2026-3129 | Media (6.4) | 0.33% | — | 28 ago 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used… |
| CVE-2026-18978 | Alta (7.2) | 0.37% | — | 28 ago 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This… |
| CVE-2026-3375 | Alta (7.2) | 0.44% | — | 27 may 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and… |
| CVE-2025-12450 | Media (6.1) | 0.38% | — | 29 oct 2025 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-50550 | Crítica (9.8) | 0.90% | — | 29 oct 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1. |
| CVE-2024-44000 | Crítica (9.8) | 82% | — | 20 oct 2024 | Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1. |
| CVE-2024-47637 | Alta (8.8) | 0.65% | — | 16 oct 2024 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1. |
| CVE-2024-47374 | Media (6.1) | 1.4% | — | 5 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a… |
| CVE-2024-47373 | Media (5.4) | 0.26% | — | 5 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a… |
| CVE-2024-9169 | Media (4.8) | 0.28% | — | 25 sept 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping.… |
| CVE-2024-28000 | Crítica (9.8) | 68% | — | 21 ago 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. |
| CVE-2024-3246 | Media (5.4) | 0.18% | — | 24 jul 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for… |
| CVE-2023-45000 | Media (5.3) | 0.41% | — | 16 abr 2024 | Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7. |
| CVE-2023-40000 | Media (6.1) | 55% | — | 16 abr 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7. |
| CVE-2023-4372 | Media (5.4) | 17% | — | 11 ene 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user… |
| CVE-2022-46800 | Alta (8.8) | 0.26% | — | 25 may 2023 | Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions. |
| CVE-2021-24964 | Media (6.1) | 1.2% | — | 3 ene 2022 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For… |
| CVE-2021-24963 | Media (4.8) | 0.65% | — | 3 ene 2022 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting |
| CVE-2020-29172 | Media (6.1) | 0.94% | — | 26 dic 2020 | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting. |