CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Litespeedtech 2Litespeed Cpanel Plugin Litespeed Whm PluginJun 17, 2026 Jun 14, 2026 N/A· v4 8.5 HIGH· v3 N/A· v2 LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as ex...Show more |
1Litespeedtech 2Litespeed Cpanel Plugin Litespeed Whm PluginJul 23, 2026 May 21, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /v...Show more |