Known Vulnerabilities for Litespeed.js by Litespeed.js Project
Listed below are 1 of the newest known vulnerabilities associated with "Litespeed.js" by "Litespeed.js Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54420 json | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by ... | Not Provided | 2026-06-14 | 2026-06-16 |
| CVE-2026-48172 json | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May... | Not Provided | 2026-05-21 | 2026-05-26 |
| CVE-2026-3375 json | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_cc... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2024-28000 json | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects Lit... | Not Provided | 2024-08-21 | 2026-04-29 |
| CVE-2023-45000 json | Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a th... | Not Provided | 2024-04-16 | 2026-04-28 |
| CVE-2023-40000 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies ... | Not Provided | 2024-04-16 | 2026-04-28 |
| CVE-2021-23682 json | This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.1... | 9.8 - CRITICAL | 2022-02-16 | 2022-02-24 |