Litespeedtech / Litespeed Web Server
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93903 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | CRITICAL | 9.4 | Sep 30, 2026 |
| CVE-2026-31386 | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by… | HIGH | 8.6 | Mar 16, 2026 |
| CVE-2025-54939 | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | HIGH | 7.5 | Aug 1, 2025 |
| CVE-2012-4871 | Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject… | MEDIUM | 4.3 | Sep 6, 2012 |
| CVE-2010-2333 | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte… | MEDIUM | 5.0 | Jun 18, 2010 |
| CVE-2004-0112 | security flaw | MEDIUM | 5.0 | Mar 18, 2004 |
Showing 1 to 5 of 5 CVEs