LIVE · cybersecurity feed
Live wire
vendor2 exploited in the wild

Litespeedtech

3 CVEs published in the last four months. Exploited flaws first.

Critical1
High2
Medium0
Exploited (KEV)2

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-48172exploited9.8criticallitespeed cpanel pluginLiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the 108d ago
CVE-2026-54420exploited8.5highlitespeed cpanel pluginLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p84d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-48172exploited9.8criticallitespeed cpanel pluginLiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the 108d ago
CVE-2026-54420exploited8.5highlitespeed cpanel pluginLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p84d ago
CVE-2026-313867.2highlitespeed web serverOpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability173d ago

Filter the full tracker by Litespeedtech