LiteSpeed Technologies Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for LiteSpeed Technologies products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
2
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
LiteSpeed Technologies KEVs Added by Year
3 LiteSpeed Technologies KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-54420
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web... |
cPanel Plugin | Confirmed | In CISA | 14 Jun 2026 |
|
CVE-2026-48172
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is... |
cPanel Plugin, WHM Plugin | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-28000
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability |
LiteSpeed Cache | High | Not in CISA | 21 Aug 2024 |
Common Vulnerability Classes (CWE)
- CWE-266 — Incorrect Privilege Assignment 2
- CWE-61 — UNIX Symbolic Link (Symlink) Following 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology