Skip to main content

Vendor/product archive

litespeedtech / openlitespeed CVEs

Beta · best-effort

12 CVEs tagged to litespeedtech / openlitespeed1 Critical, 6 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2022-0074

Published Oct 27, 2022

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-0073

Published Oct 27, 2022

Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-0072

Published Oct 27, 2022

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 t…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-26758

Published Apr 7, 2021

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5519

Published Jan 6, 2020

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19792

Published Dec 3, 2018

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a sy…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19791

Published Dec 3, 2018

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1