CVE-2026-76579
- EPSS 0.23%
- Veröffentlicht 19.09.2026 08:27:23
- Zuletzt bearbeitet 21.09.2026 13:33:33
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
CVE-2026-3129
- EPSS 0.19%
- Veröffentlicht 28.08.2026 03:39:35
- Zuletzt bearbeitet 29.08.2026 00:16:37
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` ...
CVE-2026-18978
- EPSS 0.27%
- Veröffentlicht 28.08.2026 03:39:34
- Zuletzt bearbeitet 28.08.2026 20:17:23
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
CVE-2026-3375
- EPSS 0.36%
- Veröffentlicht 27.05.2026 07:45:55
- Zuletzt bearbeitet 27.05.2026 14:50:47
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept...
CVE-2025-12450
- EPSS 0.39%
- Veröffentlicht 29.10.2025 09:27:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated att...
CVE-2024-50550
- EPSS 0.91%
- Veröffentlicht 29.10.2024 10:15:04
- Zuletzt bearbeitet 23.04.2026 15:20:10
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
CVE-2024-44000
- EPSS 82.14%
- Veröffentlicht 20.10.2024 12:15:03
- Zuletzt bearbeitet 23.04.2026 15:18:57
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
CVE-2024-47637
- EPSS 0.65%
- Veröffentlicht 16.10.2024 14:15:06
- Zuletzt bearbeitet 23.04.2026 15:19:23
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
CVE-2024-47373
- EPSS 0.25%
- Veröffentlicht 05.10.2024 16:15:03
- Zuletzt bearbeitet 23.04.2026 15:19:15
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.
CVE-2024-47374
- EPSS 1.38%
- Veröffentlicht 05.10.2024 16:15:03
- Zuletzt bearbeitet 23.04.2026 15:19:16
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.