Home/Product/litespeedtech litespeed cache
Product

litespeedtech litespeed cache

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-50550
< 6.5.2
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation
8.1HIGH
CVE-2024-44000
< 6.5.0.1
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication
9.8CRITICAL
CVE-2024-47637
< 6.5.1
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue a
8.8HIGH
CVE-2024-47374
< 6.5.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteS
7.1HIGH
CVE-2024-47373
< 6.5.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteS
6.5MEDIUM
CVE-2024-9169
< 6.5
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up
5.5MEDIUM
CVE-2024-28000
>= 1.9 and < 6.4
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpee
9.8CRITICAL
CVE-2024-3246
< 6.3
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1
6.1MEDIUM
CVE-2023-45000
< 5.7.0.1
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through
8.2HIGH
CVE-2023-40000
< 5.7.0.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteS
8.3HIGH
CVE-2023-4372
<= 5.6
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, a
6.4MEDIUM
CVE-2022-46800
<= 5.3
Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.
5.4MEDIUM
CVE-2021-24964
< 4.4.4
The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allow
6.1MEDIUM
CVE-2021-24963
< 4.4.4
The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of
4.8MEDIUM
CVE-2020-29172
< 3.6.1
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Serve
6.1MEDIUM
threatengine.sh