Openlitespeed Litespeedtech Openlitespeed

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Litespeedtech Openlitespeed.

By the Year

In 2026 there have been 1 vulnerability in Litespeedtech Openlitespeed with an average score of 7.2 out of ten. Openlitespeed did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 1 7.20
2025 0 0.00
2024 1 0.00
2023 1 7.50
2022 3 7.80
2021 1 8.80
2020 1 9.80
2019 0 0.00
2018 2 6.60

It may take a day or so for new Openlitespeed vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Litespeedtech Openlitespeed Security Vulnerabilities

Stored XSS in OpenLiteSpeed 1.7.9 Dashboard Notes
CVE-2021-47855 7.2 - High - January 21, 2026

Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.

XSS

OpenLiteSpeed <1.8.1: Chunked Encoding Mishandle (CVE-2024-31617)
CVE-2024-31617 - May 22, 2024

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

OpenLiteSpeed <1.7.18 Lacks Strict HTTP Header Validation
CVE-2023-40518 7.5 - High - August 14, 2023

LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

Untrusted Search Path -> PrivEsc in OpenLiteSpeed (1.7.16.1)
CVE-2022-0074 8.8 - High - October 27, 2022

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

Untrusted Path

Command Injection in OpenLiteSpeed Web Server <1.7.16.1
CVE-2022-0073 8.8 - High - October 27, 2022

Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.

Improper Input Validation

Directory Traversal in OpenLiteSpeed 1.5.11-1.6.20.1, <=1.7.15.9
CVE-2022-0072 5.8 - Medium - October 27, 2022

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1

Directory traversal

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8
CVE-2021-26758 8.8 - High - April 07, 2021

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.

Improper Privilege Management

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs
CVE-2020-5519 9.8 - Critical - January 06, 2020

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.

Improper Input Validation

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences
CVE-2018-19791 6.5 - Medium - December 03, 2018

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.

Improper Input Validation

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6
CVE-2018-19792 6.7 - Medium - December 03, 2018

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.

Buffer Overflow

Use-after-free vulnerability in Open Litespeed before 1.3.10.
CVE-2015-3890 7.5 - High - September 20, 2017

Use-after-free vulnerability in Open Litespeed before 1.3.10.

Dangling pointer

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Litespeedtech Openlitespeed or by Litespeedtech? Click the Watch button to subscribe.

subscribe