Litespeedtech

Litespeed Cache

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 25.09.2024 09:15:03
  • Zuletzt bearbeitet 26.09.2024 13:32:02

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...

Medienbericht Exploit
  • EPSS 68.27%
  • Veröffentlicht 21.08.2024 14:15:08
  • Zuletzt bearbeitet 29.04.2026 10:16:32

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

  • EPSS 0.18%
  • Veröffentlicht 24.07.2024 04:15:04
  • Zuletzt bearbeitet 21.11.2024 09:29:14

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update t...

  • EPSS 0.41%
  • Veröffentlicht 16.04.2024 18:15:10
  • Zuletzt bearbeitet 28.04.2026 19:21:27

Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.

Exploit
  • EPSS 54.87%
  • Veröffentlicht 16.04.2024 18:15:10
  • Zuletzt bearbeitet 28.04.2026 19:21:06

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

  • EPSS 19.68%
  • Veröffentlicht 11.01.2024 09:15:46
  • Zuletzt bearbeitet 08.04.2026 17:17:02

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it ...

  • EPSS 0.26%
  • Veröffentlicht 25.05.2023 09:15:11
  • Zuletzt bearbeitet 21.11.2024 07:31:04

Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions.

Exploit
  • EPSS 1.22%
  • Veröffentlicht 03.01.2022 13:15:08
  • Zuletzt bearbeitet 22.05.2025 19:15:24

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one o...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 03.01.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:54:05

The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting

  • EPSS 0.93%
  • Veröffentlicht 26.12.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:46

A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.