Litespeedtech Openlitespeed
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Litespeedtech Openlitespeed.
By the Year
In 2026 there have been 1 vulnerability in Litespeedtech Openlitespeed with an average score of 7.2 out of ten. Openlitespeed did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 7.20 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 0.00 |
| 2023 | 1 | 7.50 |
| 2022 | 3 | 7.80 |
| 2021 | 1 | 8.80 |
| 2020 | 1 | 9.80 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 6.60 |
It may take a day or so for new Openlitespeed vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Litespeedtech Openlitespeed Security Vulnerabilities
Stored XSS in OpenLiteSpeed 1.7.9 Dashboard Notes
CVE-2021-47855
7.2 - High
- January 21, 2026
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
XSS
OpenLiteSpeed <1.8.1: Chunked Encoding Mishandle (CVE-2024-31617)
CVE-2024-31617
- May 22, 2024
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
OpenLiteSpeed <1.7.18 Lacks Strict HTTP Header Validation
CVE-2023-40518
7.5 - High
- August 14, 2023
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
Untrusted Search Path -> PrivEsc in OpenLiteSpeed (1.7.16.1)
CVE-2022-0074
8.8 - High
- October 27, 2022
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.
Untrusted Path
Command Injection in OpenLiteSpeed Web Server <1.7.16.1
CVE-2022-0073
8.8 - High
- October 27, 2022
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.
Improper Input Validation
Directory Traversal in OpenLiteSpeed 1.5.11-1.6.20.1, <=1.7.15.9
CVE-2022-0072
5.8 - Medium
- October 27, 2022
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Directory traversal
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8
CVE-2021-26758
8.8 - High
- April 07, 2021
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.
Improper Privilege Management
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs
CVE-2020-5519
9.8 - Critical
- January 06, 2020
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
Improper Input Validation
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences
CVE-2018-19791
6.5 - Medium
- December 03, 2018
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.
Improper Input Validation
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6
CVE-2018-19792
6.7 - Medium
- December 03, 2018
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.
Buffer Overflow
Use-after-free vulnerability in Open Litespeed before 1.3.10.
CVE-2015-3890
7.5 - High
- September 20, 2017
Use-after-free vulnerability in Open Litespeed before 1.3.10.
Dangling pointer
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Litespeedtech Openlitespeed or by Litespeedtech? Click the Watch button to subscribe.