Critical1
High2
Medium0
Exploited (KEV)2
Patch these first
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-48172exploited | 9.8 | critical | litespeed cpanel plugin | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the | 108d ago |
| CVE-2026-54420exploited | 8.5 | high | litespeed cpanel plugin | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p | 84d ago |
All recent CVEs
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-48172exploited | 9.8 | critical | litespeed cpanel plugin | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the | 108d ago |
| CVE-2026-54420exploited | 8.5 | high | litespeed cpanel plugin | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p | 84d ago |
| CVE-2026-31386 | 7.2 | high | litespeed web server | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability | 173d ago |