LiteSpeed Technologies Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for LiteSpeed Technologies products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

2

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

LiteSpeed Technologies KEVs Added by Year

Loading...

3 LiteSpeed Technologies KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-54420

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web...

Confirmed In CISA 14 Jun 2026
CVE-2026-48172

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is...

Confirmed In CISA 01 Jun 2026
CVE-2024-28000

WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

High Not in CISA 21 Aug 2024

Common Vulnerability Classes (CWE)

  • CWE-266 — Incorrect Privilege Assignment 2
  • CWE-61 — UNIX Symbolic Link (Symlink) Following 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology