Vulnerabilities > Litespeedtech > Litespeed Cache > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-24 CVE-2024-3246 Cross-Site Request Forgery (CSRF) vulnerability in Litespeedtech Litespeed Cache
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1.
network
low complexity
litespeedtech CWE-352
5.4
2024-01-11 CVE-2023-4372 Cross-site Scripting vulnerability in Litespeedtech Litespeed Cache
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
litespeedtech CWE-79
5.4
2020-12-26 CVE-2020-29172 Cross-site Scripting vulnerability in Litespeedtech Litespeed Cache
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
4.3