Litespeedtech Litespeed Cache
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Litespeedtech Litespeed Cache.
By the Year
In 2026 there have been 4 vulnerabilities in Litespeedtech Litespeed Cache with an average score of 6.4 out of ten. Last year, in 2025 Litespeed Cache had 1 security vulnerability published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.28.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 6.38 |
| 2025 | 1 | 6.10 |
| 2024 | 11 | 7.23 |
| 2023 | 1 | 5.40 |
| 2022 | 2 | 5.45 |
It may take a day or so for new Litespeed Cache vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Litespeedtech Litespeed Cache Security Vulnerabilities
LiteSpeed Cache WP Plugin 7.9 Reflected XSS in 'esi' param
CVE-2026-76579
4.7 - Medium
- September 19, 2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the attacker supply a validly signed 'esi' value in the GET query string while submitting a separate attacker-controlled 'esi' payload as a POST body field, relying on PHP's default $_REQUEST merge order to have the POST value take precedence at the point of execution.
XSS
LiteSpeed Cache WP Plugin <=7.7 XSS via img attrs
CVE-2026-3129
6.4 - Medium
- August 28, 2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page.
XSS
LiteSpeed Cache <=7.8.1 Stored XSS in Comment Content
CVE-2026-18978
7.2 - High
- August 28, 2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. ", <, >) placed inside an allowed element such as <code> bypasses WordPress's wp_kses sanitization, as kses does not treat a data-settings="..." substring within text content as an HTML attribute, allowing the malicious payload to reach the vulnerable function. For this to be exploitable, the site must allow users with previously approved comments to write new comments, and the require_name_email setting must be disabled.
XSS
WordPress LiteSpeed Cache <=7.7 Stored XSS via notify_ccss/notify_ucss
CVE-2026-3375
7.2 - High
- May 27, 2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend page loads without output escaping. The access control protecting these endpoints is IP-based validation that can potentially be bypassed when the WordPress site is deployed behind a reverse proxy, load balancer, or CDN with certain configurations. This makes it possible for unauthenticated attackers, under certain conditions, to inject arbitrary JavaScript into CCSS/UCSS content.
XSS
Reflected XSS in LSCache WP Plugin ( v7.5.0.1)
CVE-2025-12450
6.1 - Medium
- October 29, 2025
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
XSS
Privilege Escalation in LiteSpeed Cache v6.5.1
CVE-2024-50550
8.1 - High
- October 29, 2024
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
Incorrect Privilege Assignment
Auth Bypass in LiteSpeed Cache <6.5.0.1 (Insufficiently Protected Credentials)
CVE-2024-44000
9.8 - Critical
- October 20, 2024
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
Insufficiently Protected Credentials
LiteSpeed Cache <=6.4.1: Relative Path Traversal Vulnerability
CVE-2024-47637
8.8 - High
- October 16, 2024
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
Relative Path Traversal
LiteSpeed Cache XSS: Stored XSS in versions 6.5.0.2 (CVE-2024-47374)
CVE-2024-47374
7.1 - High
- October 05, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.
XSS
LiteSpeed Cache <=6.5.0.2 Stored XSS Vulnerability
CVE-2024-47373
6.5 - Medium
- October 05, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.
XSS
Stored XSS in LiteSpeed Cache plugin <=6.4.1 via debug settings
CVE-2024-9169
5.5 - Medium
- September 25, 2024
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
XSS
Priv Escalation in LiteSpeed Cache 1.9-6.3.0.1 via Incorrect Priv Assignment
CVE-2024-28000
9.8 - Critical
- August 21, 2024
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
Incorrect Privilege Assignment
LS Cache WP Plugin CVE-2024-3246: XSRF via Invalid Nonce (6.2.0.1)
CVE-2024-3246
6.1 - Medium
- July 24, 2024
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the token setting and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Session Riding
Stored XSS in LiteSpeed Cache (<=5.7)
CVE-2023-40000
6.1 - Medium
- April 16, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
XSS
Missing Auth in LiteSpeed Cache v<=5.7 (CVE-2023-45000)
CVE-2023-45000
5.3 - Medium
- April 16, 2024
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.
AuthZ
Stored XSS via 'esi' Shortcode in LiteSpeed Cache Plugin <=5.6
CVE-2023-4372
6.4 - Medium
- January 11, 2024
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
LiteSpeed Cache plugin <=5.3 CSRF Vulnerability
CVE-2022-46800
5.4 - Medium
- May 25, 2023
Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.
Session Riding
The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify
CVE-2021-24964
6.1 - Medium
- January 03, 2022
The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.
XSS
The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page
CVE-2021-24963
4.8 - Medium
- January 03, 2022
The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Litespeedtech Litespeed Cache or by Litespeedtech? Click the Watch button to subscribe.