Litespeedtech
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Litespeedtech product.
RSS Feeds for Litespeedtech security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Litespeedtech products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Litespeedtech Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 6 vulnerabilities in Litespeedtech with an average score of 6.9 out of ten. Last year, in 2025 Litespeedtech had 1 security vulnerability published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.82.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 6.92 |
| 2025 | 1 | 6.10 |
| 2024 | 13 | 7.44 |
| 2023 | 2 | 6.45 |
| 2022 | 6 | 7.35 |
| 2021 | 1 | 8.80 |
| 2020 | 1 | 9.80 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 6.60 |
It may take a day or so for new Litespeedtech vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Litespeedtech Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76579 | Sep 19, 2026 |
LiteSpeed Cache WP Plugin 7.9 Reflected XSS in 'esi' paramThe LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution. |
|
| CVE-2026-3129 | Aug 28, 2026 |
LiteSpeed Cache WP Plugin <=7.7 XSS via img attrsThe LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page. |
|
| CVE-2026-18978 | Aug 28, 2026 |
LiteSpeed Cache <=7.8.1 Stored XSS in Comment ContentThe LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. ", <, >) placed inside an allowed element such as <code> bypasses WordPress's wp_kses sanitization, as kses does not treat a data-settings="..." substring within text content as an HTML attribute, allowing the malicious payload to reach the vulnerable function. For this to be exploitable, the site must allow users with previously approved comments to write new comments, and the require_name_email setting must be disabled. |
|
| CVE-2026-3375 | May 27, 2026 |
WordPress LiteSpeed Cache <=7.7 Stored XSS via notify_ccss/notify_ucssThe LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend page loads without output escaping. The access control protecting these endpoints is IP-based validation that can potentially be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations. This makes it possible for unauthenticated attackers, under certain conditions, to inject arbitrary JavaScript into CCSS/UCSS content. |
|
| CVE-2021-47903 | Jan 23, 2026 |
Command Injection via 'Command' in LWS Enterprise 5.4.11 ConfigLiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection. |
|
| CVE-2021-47855 | Jan 21, 2026 |
Stored XSS in OpenLiteSpeed 1.7.9 Dashboard NotesOpenlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon. |
|
| CVE-2025-12450 | Oct 29, 2025 |
Reflected XSS in LSCache WP Plugin ( v7.5.0.1)The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. |
|
| CVE-2024-50550 | Oct 29, 2024 |
Privilege Escalation in LiteSpeed Cache v6.5.1Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1. |
|
| CVE-2024-44000 | Oct 20, 2024 |
Auth Bypass in LiteSpeed Cache <6.5.0.1 (Insufficiently Protected Credentials)Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1. |
|
| CVE-2024-47637 | Oct 16, 2024 |
LiteSpeed Cache <=6.4.1: Relative Path Traversal VulnerabilityRelative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1. |
|