Known Vulnerabilities for Openlitespeed by Litespeedtech
Listed below are 9 of the newest known vulnerabilities associated with "Openlitespeed" by "Litespeedtech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-40518 json | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers. | 7.5 - HIGH | 2023-08-14 | 2023-08-22 |
| CVE-2022-0074 json | Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container all... | 8.8 - HIGH | 2022-10-27 | 2023-11-07 |
| CVE-2022-0073 json | Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboard... | 8.8 - HIGH | 2022-10-27 | 2023-11-07 |
| CVE-2022-0072 json | Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allo... | 5.8 - MEDIUM | 2022-10-27 | 2023-11-07 |
| CVE-2021-26758 json | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal ... | 8.8 - HIGH | 2021-04-07 | 2021-04-12 |
| CVE-2020-5519 json | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Conf... | 9.8 - CRITICAL | 2020-01-06 | 2020-01-15 |
| CVE-2018-19792 json | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or p... | 6.7 - MEDIUM | 2018-12-03 | 2019-01-31 |
| CVE-2018-19791 json | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an att... | 6.5 - MEDIUM | 2018-12-03 | 2019-02-05 |
| CVE-2015-3890 json | Use-after-free vulnerability in Open Litespeed before 1.3.10. | 7.5 - HIGH | 2017-09-20 | 2020-07-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Litespeedtech | Openlitespeed | 1.7.3 | |||
| Application | Litespeedtech | Openlitespeed | 1.7.2 | |||
| Application | Litespeedtech | Openlitespeed | 1.7.1 | |||
| Application | Litespeedtech | Openlitespeed | 1.7.0 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.9 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.8 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.7 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.6 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.5 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.4 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.3 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.2 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.14 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.13 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.12 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.11 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.10 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.1 | |||
| Application | Litespeedtech | Openlitespeed | 1.6.0 | |||
| Application | Litespeedtech | Openlitespeed | 1.5.9 |