Litespeed Web Server Litespeedtech Litespeed Web Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Litespeedtech Litespeed Web Server.

By the Year

In 2026 there have been 1 vulnerability in Litespeedtech Litespeed Web Server with an average score of 8.8 out of ten.

Year Vulnerabilities Average Score
2026 1 8.80

It may take a day or so for new Litespeed Web Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Litespeedtech Litespeed Web Server Security Vulnerabilities

Command Injection via 'Command' in LWS Enterprise 5.4.11 Config
CVE-2021-47903 8.8 - High - January 23, 2026

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.

Shell injection

Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11
CVE-2012-4871 - September 06, 2012

Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Litespeedtech Litespeed Web Server or by Litespeedtech? Click the Watch button to subscribe.

subscribe