VendorsLiteSpeedTechlitespeed_web_serverall versions
Vulnerabilities

LiteSpeedTech LiteSpeed Technologies LiteSpeed Web Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-31386
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.
Published 2026-03-16 · Analyzed
8.6EPSS 0.015
CVE-2025-54939
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Published 2025-08-01 · Analyzed
7.5EPSS 0.008
CVE-2010-2333
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
Published 2010-06-18 · Modified
5.01 PoCEPSS 0.602
CVE-2004-0112
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Published 2004-03-18 · Modified
5.0EPSS 0.104
CVE-2012-4871
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.
Published 2012-09-06 · Modified
4.31 PoCEPSS 0.016