- Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
- Source
- audit@patchstack.com
- NVD status
- Modified
- Products
- litespeed_cache
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- audit@patchstack.com
- CWE-79
- Hype score
- Not currently trending
SolarWinds Web Help Desk has a critical pre-auth RCE chain (CVE-2023-40000-02). Unauthenticated attackers can execute code on the server. Patch to v12.8.2 or later. Stay ahead of attackers. Follow for daily updates.
@cybrmaker
2 Mar 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2023-40000 - high 🚨 LiteSpeed Cache <= 5.7 - Unauthenticated Stored XSS > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') ... 👾 https://t.co/TUmvZtYocq @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
19 Sept 2025
254 Impressions
0 Retweets
6 Likes
4 Bookmarks
0 Replies
0 Quotes
Threat Alert: LiteSpeed Cache WordPress plugin bug lets hackers get admin access CVE-2024-50550 CVE-2023-40000 CVE-2024-28000 Severity: ⚠️ Critical Maturity: 💥 Mainstream Learn more: https://t.co/LoSwPs80iG #CyberSecurity #ThreatIntel #InfoSec (1/3)
@fletch_ai
31 Oct 2024
32 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:litespeedtech:litespeed_cache:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "967FB0CF-DC74-4455-8237-A277E95FE632",
"versionEndExcluding": "5.7.0.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]