PoC Archive PoC Archive

tag

LiteSpeed

  • CVE-2026-54420 network HIGH 8.5 KEV

    LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420

    LiteSpeed's cPanel and WHM plugins mishandle user-supplied symbolic links on shared hosting servers isolated with CloudLinux/CageFS. A tenant with FTP or web shell access to their own account can create a symlink (via SITE SYMLINK, rename-based tricks, or…

    Unverified 2026-07-05
  • CVE-2026-48172 web HIGH KEV EPSS 19%

    LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172)

    CVE-2026-48172 is a local privilege-escalation flaw in LiteSpeed cPanel Plugin v6.5.0 and earlier. The plugin installation flow does not sufficiently validate package ownership/permissions and can be abused with symlinked install targets. A normal cPanel user…

    Unverified 2026-05-30