A server-side request forgery vulnerability reported by Patchstack has been announced. Please upgrade to v7.9.1 or later.
A cross-site scripting vulnerability reported by WordFence has been assigned CVE-2026-18978. Please upgrade to v7.9 or later.
A cross-site scripting vulnerability reported by WordFence has been assigned CVE-2026-3129. Please upgrade to v7.8 or later.
LiteSpeed server products are effectively not vulnerable to HTTP/2 Bomb attacks. Learn why here.
We have an urgent security update for LiteSpeed’s user-end plugin for cPanel and WHM plugin. Please upgrade to the latest versions ASAP.
We have a security update for LiteSpeed Cache for WordPress. A few months ago, we were made aware of a vulnerability in the LiteSpeed Cache for …
We have an urgent security update for LiteSpeed’s user-end plugin for cPanel and WHM plugin. Please upgrade to the latest versions ASAP.
We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We …
We have a security update for LiteSpeed’s QUIC and HTTP/3 Library (LSQUIC), and all three LiteSpeed server products. Recently we were made aware of a vulnerability …






