VendorsLiteSpeedTechlitespeed_cacheany version
Vulnerabilities

LiteSpeedTech LiteSpeed Cache any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2024-44000
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
Published 2024-10-20 · Modified
9.81 PoCEPSS 0.823
CVE-2024-28000
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
Published 2024-08-21 · Modified
9.81 PoCEPSS 0.683
CVE-2024-50550
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
Published 2024-10-29 · Modified
9.8EPSS 0.009
CVE-2024-47637
WordPress LiteSpeed Cache plugin <= 6.4.1 - Path Traversal vulnerability
Published 2024-10-16 · Modified
8.8EPSS 0.006
CVE-2022-46800
WordPress LiteSpeed Cache Plugin <= 5.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-05-25 · Modified
8.8EPSS 0.003
CVE-2023-40000
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
Published 2024-04-16 · Modified
8.3EPSS 0.549
CVE-2023-45000
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Broken Access Control on API vulnerability
Published 2024-04-16 · Modified
8.2EPSS 0.004
CVE-2024-47374
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-05 · Modified
7.1EPSS 0.014
CVE-2024-47373
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-05 · Modified
6.5EPSS 0.003
CVE-2023-4372
LiteSpeed Cache <= 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-01-11 · Modified
6.4EPSS 0.168
CVE-2021-24964
LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS
Published 2022-01-03 · Modified
6.1EPSS 0.012
CVE-2020-29172
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
Published 2020-12-26 · Modified
6.1EPSS 0.009
CVE-2024-3246
LiteSpeed Cache <= 6.2.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Published 2024-07-24 · Modified
6.1EPSS 0.002
CVE-2024-9169
litespeed cache <= 6.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Published 2024-09-25 · Analyzed
5.5EPSS 0.003
CVE-2021-24963
LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting
Published 2022-01-03 · Modified
4.8EPSS 0.007