Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54420

Опубликовано: 14 июн. 2026
Источник: nvd
CVSS3: 8.5
EPSS Низкий

Описание

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:*
Версия до 2.4.8 (исключая)
cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*
Версия до 5.3.2.0 (исключая)

EPSS

Процентиль: 71%
0.01439
Низкий

8.5 High

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 8.5
github
2 месяца назад

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

EPSS

Процентиль: 71%
0.01439
Низкий

8.5 High

CVSS3

Дефекты

CWE-61