Litespeedtech Litespeedtech

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Litespeedtech product.

RSS Feeds for Litespeedtech security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Litespeedtech products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Litespeedtech Sorted by Most Security Vulnerabilities since 2018

Litespeedtech Litespeed Cache19 vulnerabilities

Litespeedtech Openlitespeed11 vulnerabilities

Litespeedtech Lsquic2 vulnerabilities

By the Year

In 2026 there have been 6 vulnerabilities in Litespeedtech with an average score of 6.9 out of ten. Last year, in 2025 Litespeedtech had 1 security vulnerability published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.82.




Year Vulnerabilities Average Score
2026 6 6.92
2025 1 6.10
2024 13 7.44
2023 2 6.45
2022 6 7.35
2021 1 8.80
2020 1 9.80
2019 0 0.00
2018 2 6.60

It may take a day or so for new Litespeedtech vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Litespeedtech Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-76579 Sep 19, 2026
LiteSpeed Cache WP Plugin 7.9 Reflected XSS in 'esi' param The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.
Litespeed Cache
CVE-2026-3129 Aug 28, 2026
LiteSpeed Cache WP Plugin <=7.7 XSS via img attrs The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page.
Litespeed Cache
CVE-2026-18978 Aug 28, 2026
LiteSpeed Cache <=7.8.1 Stored XSS in Comment Content The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. &#34;, &#60;, &#62;) placed inside an allowed element such as &lt;code&gt; bypasses WordPress's wp_kses sanitization, as kses does not treat a data-settings="..." substring within text content as an HTML attribute, allowing the malicious payload to reach the vulnerable function. For this to be exploitable, the site must allow users with previously approved comments to write new comments, and the require_name_email setting must be disabled.
Litespeed Cache
CVE-2026-3375 May 27, 2026
WordPress LiteSpeed Cache <=7.7 Stored XSS via notify_ccss/notify_ucss The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend page loads without output escaping. The access control protecting these endpoints is IP-based validation that can potentially be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations. This makes it possible for unauthenticated attackers, under certain conditions, to inject arbitrary JavaScript into CCSS/UCSS content.
Litespeed Cache
CVE-2021-47903 Jan 23, 2026
Command Injection via 'Command' in LWS Enterprise 5.4.11 Config LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
Litespeed Web Server
CVE-2021-47855 Jan 21, 2026
Stored XSS in OpenLiteSpeed 1.7.9 Dashboard Notes Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Openlitespeed
CVE-2025-12450 Oct 29, 2025
Reflected XSS in LSCache WP Plugin ( v7.5.0.1) The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Litespeed Cache
CVE-2024-50550 Oct 29, 2024
Privilege Escalation in LiteSpeed Cache v6.5.1 Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
Litespeed Cache
CVE-2024-44000 Oct 20, 2024
Auth Bypass in LiteSpeed Cache <6.5.0.1 (Insufficiently Protected Credentials) Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
Litespeed Cache
CVE-2024-47637 Oct 16, 2024
LiteSpeed Cache <=6.4.1: Relative Path Traversal Vulnerability Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
Litespeed Cache
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.