یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
زیاد بهره‌برداری واقعی گزارش شده EPSS 0.8% اولویت 55/100

CVE-2026-54420— LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.

انتشار: 2026-05-31 00:00 آخرین مشاهده داده: 2026-09-15 17:46 3 منبع · 3 رسمیاعتماد خوب · 69/100
اولویت VulnWatch 55/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS — / 0.8% شدت فنی / احتمال بهره‌برداری
کیفیت داده 67/100 نیازمند توجه · اعتماد خوب
تازگی در حال قدیمی‌شدن به‌روز در ۳۰ روز · 3 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

اقدام فوری / بررسی سریع
بهره‌برداری واقعیاین CVE در CISA KEV ثبت شده است؛ مواجهه و نسخه نصب‌شده را سریع بررسی کنید.
EPSS 0.8%سیگنال EPSS پایین‌تر است؛ سایر شاخص‌ها را نیز در تصمیم لحاظ کنید.
کیفیت داده 67/100نیازمند توجه · 3 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار در این صفحه ثبت شده است؛ بخش راهکار پیشنهادی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority60
KEV / بهره‌برداری شناخته‌شدهشدت بالاراهکار اجرایی موجود
01

خلاصه آسیب‌پذیری

A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.
02

توضیحات کامل

LiteSpeed Blog / Products / LiteSpeed Web Server / Security Update for LiteSpeed cPanel Plugin Security Update for LiteSpeed cPanel Plugin June 1st, 2026 by Lisa Clarke LiteSpeed Web Server , Security 0 Comments We have another urgent security update for LiteSpeed’s user-end plugin for cPanel. Last night we were made aware of a vulnerability affecting our user-end cPanel plugin (LiteSpeed’s WHM plugin was not affected). We patched this vulnerability in v2.4.8. Please update to the latest version of the cPanel user-end plugin, which is bundled with the WHM plugin.. This Privilege Escalation vulnerability, which was reported to us by the team at Namecheap, has been assigned CVE-2026-54420. Impact A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8. Use the following command to determine if your server has been affected: grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null If there is no output, then your server has not been affected. If this command results in any output, the vulnerability may have been exploited on your server. There can be false positives, so look for the following to confirm: Pairing: generateEcCert immediately followed by packageUserSize for the same user (legitimate UI flows don’t chain these) Concurrency: 7–10 concurrent calls per attempt (legitimate UI does one at a time) Same source IP hammering both endpoints To determine any damage done, examine the system logs for any actions taken by the detected IPs. If you need assistance, you may contact our support team. Actions We urgently recommend that those using the LiteSpeed user-end plugin for cPanel upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled w/ cPanel plugin v2.4.8) or higher to patch this vulnerability. To update the WHM plugin, run this command, which will also update the user-end plugin, if you currently have it installed: wget -O- https://litespeedtech.com/packages/cpanel/lsws_whm_plugin_install.sh | sh If you cannot upgrade at this time, you can use the following command to remove the user-end plugin and avoid this vulnerability: /usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall Once you’ve updated the WHM plugin, you can run the following commands, which will reinstall the user-end plugin and turn on autoinstall: /usr/local/lsws/admin/misc/lscmctl cpanelplugin --install /usr/local/lsws/admin/misc/lscmctl cpanelplugin -autoinstall 1 Timeline May 31, 2026: We were alerted to the original issue. May 31, 2026: cPanel pushed an uninstall command for the user-end plugin Jun 1, 2026: We released cPanel plugin v2.4.8 and WHM plugin v5.3.2.1 Jun 1, 2026: We applied for a CVE Jun 14, 2026: CVE-2026-54420 was assigned Conclusion We thank Namecheap for bringing the original issue to our attention. We’d also like to thank the cPanel team for their immediate action in preventing further exploitation on additional servers. The vulnerability has been patched, so if you are keeping your cPanel plugin up-to-date, there is nothing you need to do. If you have not updated in a while, please do so immediately. Share this: Print (Opens in new window) Print Email a link to a friend (Opens in new window) Email Share on Facebook (Opens in new window) Facebook Share on X (Opens in new window) X Share on Bluesky (Opens in new window) Bluesky Share on Mastodon (Opens in new window) Mastodon Share on Threads (Opens in new window) Threads Share on LinkedIn (Opens in new window) LinkedIn Share on Reddit (Opens in new window) Reddit Share on Telegram (Opens in new window) Telegram Share on WhatsApp (Opens in new window) WhatsApp Related Tags: cpanel Categories:LiteSpeed Web Server , Security Related Posts Security Update for LiteSpeed cPanel Plugin Proxy n8n with LiteSpeed Web Server Notes From the Road: cPanel Conference WpW: Autodiscovery, LSCache and the Command Line Benchmarks: LiteSpeed vs. Apache with cPanel + WordPress Comments Click here to cancel reply. Leave a Reply Name * Email * Website Comment Δdocument.getElementById( "ak_js_1" ).setAttribute( "value", ( new Date() ).getTime() ); Recent Posts September 2nd, 2026 Security Update for LSCWP August 27th, 2026 Security Update for LSCWP August 27th, 2026 Security Update for LSCWP August 13th, 2026 From Public Flop to Top Tier 3x: The WP Buzz Rebuild July 27th, 2026 Customer Showcase: LiteSpeed Performance Helps Foster Trust Related Posts Security Update for LiteSpeed cPanel Plugin Proxy n8n with LiteSpeed Web Server Notes From the Road: cPanel Conference WpW: Autodiscovery, LSCache and the Command Line Benchmarks: LiteSpeed vs. Apache with cPanel + WordPress Categories Select Category …Benchmarks (32)Company News (21)Conferences (33)Featured Posts (3)LiteMage Cache (22)LiteSpeed Web ADC (25)LiteSpeed Web Server (142)LSCache (145)OpenLiteSpeed (51)Performance (75)Products (1)QUIC Cloud (6)Security (48)Troubleshooting (9) Archives Select Month ... September 2026 (1) August 2026 (3) July 2026 (1) June 2026 (2) May 2026 (4) October 2025 (1) August 2025 (2) July 2025 (1) June 2025 (1) May 2025 (1) March 2025 (2) February 2025 (1) January 2025 (1) December 2024 (1) November 2024 (1) October 2024 (1) September 2024 (1) August 2024 (3) April 2024 (1) March 2024 (1) February 2024 (2) January 2024 (1) December 2023 (1) November 2023 (1) October 2023 (1) June 2023 (2) May 2023 (1) April 2023 (3) March 2023 (2) February 2023 (1) January 2023 (2) November 2022 (3) October 2022 (2) September 2022 (1) August 2022 (2) June 2022 (1) March 2022 (1) January 2022 (1) December 2021 (1) July 2021 (1) June 2021 (4) April 2021 (2) March 2021 (4) February 2021 (1) January 2021 (2) December 2020 (1) November 2020 (2) October 2020 (2) August 2020 (2) July 2020 (3) June 2020 (2) March 2020 (1) February 2020 (2) January 2020 (2) December 2019 (3) November 2019 (1) October 2019 (5) September 2019 (2) August 2019 (1) July 2019 (2) June 2019 (2) May 2019 (2) April 2019 (2) March 2019 (3) January 2019 (2) December 2018 (2) November 2018 (3) October 2018 (2) September 2018 (4) August 2018 (2) July 2018 (2) June 2018 (5) May 2018 (5) April 2018 (9) March 2018 (8) February 2018 (6) January 2018 (10) December 2017 (6) November 2017 (5) October 2017 (10) September 2017 (8) August 2017 (6) July 2017 (5) June 2017 (6) May 2017 (5) April 2017 (1) February 2017 (4) December 2016 (1) November 2016 (1) October 2016 (1) September 2016 (1) August 2016 (1) July 2016 (1) June 2016 (1) May 2016 (2) April 2016 (7) March 2016 (4) February 2016 (2) January 2016 (1) December 2015 (4) November 2015 (2) October 2015 (1) September 2015 (1) August 2015 (1) July 2015 (4) June 2015 (1) May 2015 (1) April 2015 (2) March 2015 (2) February 2015 (2) January 2015 (1) December 2014 (1) November 2014 (2) October 2014 (3) September 2014 (4) August 2014 (2) July 2014 (4) June 2014 (2) May 2014 (2) April 2014 (2) March 2014 (3) February 2014 (3) January 2014 (3) December 2013 (2) November 2013 (5) October 2013 (5) September 2013 (1) August 2013 (2) July 2013 (3) June 2013 (4) May 2013 (6) April 2013 (4) March 2013 (12) February 2013 (4) December 2012 (1) November 2012 (1) September 2012 (1) October 2011 (1) January 2011 (2) February 2010 (1) January 2010 (1) December 2009 (3) August 2009 (1) July 2009 (2) April 2007 (1) December 2006 (1) November 2006 (1) September 2006 (1) August 2006 (4) Subscribe to Blog via Email Enter your email address to subscribe to this blog and receive notifications of new posts by email. Email Address Subscribe
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
این دستورها از اطلاعات منبع ثبت‌شده استخراج شده‌اند. پیش از اجرا، منبع اصلی، نسخه محصول و شرایط محیط خود را بررسی کنید.
دستور رسمی 1
LiteSpeed Security Blog · رسمی · BASH
wget -O- https://litespeedtech.com/packages/cpanel/lsws_whm_plugin_install.sh | sh
مشاهده منبع ↗
دستور رسمی 2
LiteSpeed Security Blog · رسمی · BASH
/usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall
مشاهده منبع ↗
دستور رسمی 3
LiteSpeed Security Blog · رسمی · BASH
/usr/local/lsws/admin/misc/lscmctl cpanelplugin --install
/usr/local/lsws/admin/misc/lscmctl cpanelplugin -autoinstall 1
مشاهده منبع ↗
دستور رسمی 7
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot body,
#sharedLSfoot h1,
#sharedLSfoot h2,
#sharedLSfoot h3,
#sharedLSfoot h4,
#sharedLSfoot h5,
#sharedLSfoot h6 {
مشاهده منبع ↗
دستور رسمی 8
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot h1,
#sharedLSfoot h2,
#sharedLSfoot h3,
#sharedLSfoot h4,
#sharedLSfoot h5,
#sharedLSfoot h6 {
مشاهده منبع ↗
دستور رسمی 10
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links {
مشاهده منبع ↗
دستور رسمی 11
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList {
مشاهده منبع ↗
دستور رسمی 12
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList div {
مشاهده منبع ↗
دستور رسمی 13
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList h5 {
مشاهده منبع ↗
دستور رسمی 14
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList ul {
مشاهده منبع ↗
دستور رسمی 15
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList ul li {
مشاهده منبع ↗
دستور رسمی 16
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList ul li a {
مشاهده منبع ↗
دستور رسمی 17
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList ul li a:hover {
مشاهده منبع ↗
دستور رسمی 18
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.links div.linkList ul li:first-child {
مشاهده منبع ↗
دستور رسمی 19
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.socials {
مشاهده منبع ↗
دستور رسمی 20
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.socials div.networks {
مشاهده منبع ↗
دستور رسمی 21
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.socials div.networks a {
مشاهده منبع ↗
دستور رسمی 22
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.socials div.networks a:first-child {
مشاهده منبع ↗
دستور رسمی 23
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.socials div.networks a:hover {
مشاهده منبع ↗
دستور رسمی 24
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.copyright {
مشاهده منبع ↗
دستور رسمی 25
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.copyright a {
مشاهده منبع ↗
دستور رسمی 26
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section.copyright a:hover {
مشاهده منبع ↗
دستور رسمی 27
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot a.backToTop {
مشاهده منبع ↗
دستور رسمی 28
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot a.backToTop i {
مشاهده منبع ↗
دستور رسمی 29
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .nav > li > a {
مشاهده منبع ↗
دستور رسمی 30
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot body,
#sharedLSfoot ul,
#sharedLSfoot li,
#sharedLSfoot p {
مشاهده منبع ↗
دستور رسمی 31
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot * + address,
#sharedLSfoot * + blockquote,
#sharedLSfoot * + dl,
#sharedLSfoot * + fieldset,
#sharedLSfoot * + figure,
#sharedLSfoot * + ol,
#sharedLSfoot * + p,
#sharedLSfoot * + pre,
#sharedLSfoot * + ul {
مشاهده منبع ↗
دستور رسمی 32
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot address,
#sharedLSfoot blockquote,
#sharedLSfoot dl,
#sharedLSfoot fieldset,
#sharedLSfoot figure,
#sharedLSfoot ol,
#sharedLSfoot p,
#sharedLSfoot pre,
#sharedLSfoot ul {
مشاهده منبع ↗
دستور رسمی 33
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot [class*="uk-width"] {
مشاهده منبع ↗
دستور رسمی 34
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-small {
مشاهده منبع ↗
دستور رسمی 35
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-margin-bottom {
مشاهده منبع ↗
دستور رسمی 36
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-margin-top {
مشاهده منبع ↗
دستور رسمی 37
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-contrast {
مشاهده منبع ↗
دستور رسمی 38
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-container {
مشاهده منبع ↗
دستور رسمی 39
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-container:after,
#sharedLSfoot .uk-container:before {
مشاهده منبع ↗
دستور رسمی 40
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-container:after {
مشاهده منبع ↗
دستور رسمی 41
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-container-center {
مشاهده منبع ↗
دستور رسمی 42
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-container-center p {
مشاهده منبع ↗
دستور رسمی 43
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid {
مشاهده منبع ↗
دستور رسمی 44
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid::before {
مشاهده منبع ↗
دستور رسمی 45
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid > * {
مشاهده منبع ↗
دستور رسمی 46
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid-small {
مشاهده منبع ↗
دستور رسمی 47
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid-small > * {
مشاهده منبع ↗
دستور رسمی 48
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-1-1 {
مشاهده منبع ↗
دستور رسمی 49
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-small-1-1 {
مشاهده منبع ↗
دستور رسمی 50
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot section h2 {
مشاهده منبع ↗
دستور رسمی 51
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-center-small {
مشاهده منبع ↗
دستور رسمی 52
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-hidden-small {
مشاهده منبع ↗
دستور رسمی 53
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-medium-1-1 {
مشاهده منبع ↗
دستور رسمی 54
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-medium-1-3 {
مشاهده منبع ↗
دستور رسمی 55
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-center-medium {
مشاهده منبع ↗
دستور رسمی 56
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-left-medium {
مشاهده منبع ↗
دستور رسمی 57
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-large-1-1 {
مشاهده منبع ↗
دستور رسمی 58
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-large-1-6 {
مشاهده منبع ↗
دستور رسمی 59
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid>* {
مشاهده منبع ↗
دستور رسمی 60
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid + .uk-grid,
#sharedLSfoot .uk-grid-margin,
#sharedLSfoot .uk-grid > * > .uk-panel + .uk-panel {
مشاهده منبع ↗
دستور رسمی 61
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-width-xlarge-1-2 {
مشاهده منبع ↗
دستور رسمی 62
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-left {
مشاهده منبع ↗
دستور رسمی 63
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-center {
مشاهده منبع ↗
دستور رسمی 64
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-float-right {
مشاهده منبع ↗
دستور رسمی 65
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot [class*=uk-icon-] {
مشاهده منبع ↗
دستور رسمی 66
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot [class*=uk-icon-],
#sharedLSfoot [class*=uk-icon-]:focus,
#sharedLSfoot [class*=uk-icon-]:hover {
مشاهده منبع ↗
دستور رسمی 67
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-button {
مشاهده منبع ↗
دستور رسمی 68
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-copyright:before {
مشاهده منبع ↗
دستور رسمی 69
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-facebook:before {
مشاهده منبع ↗
دستور رسمی 70
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-facebook:focus,
#sharedLSfoot .uk-icon-facebook:hover {
مشاهده منبع ↗
دستور رسمی 71
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-youtube:before {
مشاهده منبع ↗
دستور رسمی 72
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-youtube:focus,
#sharedLSfoot .uk-icon-youtube:hover {
مشاهده منبع ↗
دستور رسمی 73
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-twitter:before {
مشاهده منبع ↗
دستور رسمی 74
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-twitter:focus,
#sharedLSfoot .uk-icon-twitter:hover {
مشاهده منبع ↗
دستور رسمی 75
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-instagram:before {
مشاهده منبع ↗
دستور رسمی 76
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-instagram:focus,
#sharedLSfoot .uk-icon-instagram:hover {
مشاهده منبع ↗
دستور رسمی 77
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-google-plus:before {
مشاهده منبع ↗
دستور رسمی 78
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-google-plus:focus,
#sharedLSfoot .uk-icon-google-plus:hover {
مشاهده منبع ↗
دستور رسمی 79
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-linkedin:before {
مشاهده منبع ↗
دستور رسمی 80
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-linkedin:focus,
#sharedLSfoot .uk-icon-linkedin:hover {
مشاهده منبع ↗
دستور رسمی 81
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-slack:before {
مشاهده منبع ↗
دستور رسمی 82
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-icon-slack:focus,
#sharedLSfoot .uk-icon-slack:hover {
مشاهده منبع ↗
دستور رسمی 83
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-margin-bottom-remove {
مشاهده منبع ↗
دستور رسمی 84
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-contrast {
مشاهده منبع ↗
دستور رسمی 85
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-bold {
مشاهده منبع ↗
دستور رسمی 86
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-text-warning {
مشاهده منبع ↗
دستور رسمی 87
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-link,
#sharedLSfoot a {
مشاهده منبع ↗
دستور رسمی 88
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-link:hover,
#sharedLSfoot a:hover {
مشاهده منبع ↗
دستور رسمی 89
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-contrast .uk-link,
#sharedLSfoot .uk-contrast a:not([class]) {
مشاهده منبع ↗
دستور رسمی 90
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-contrast .uk-link:hover,
#sharedLSfoot .uk-contrast a:not([class]):hover {
مشاهده منبع ↗
دستور رسمی 91
LiteSpeed Security Blog · رسمی · BASH
#sharedLSfoot .uk-grid > * > :last-child {
مشاهده منبع ↗
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
69/100
اعتماد خوب اعتماد داده 67/100 نیازمند توجه در حال قدیمی‌شدن وضعیت تازگی به‌روز در ۳۰ روز تازگی مشاهده 88/100 کامل‌بودن · کامل 75/100 پوشش منابع 3 منبع مرتبط 3 رسمی · 1 سطح ۱ 1 اختلاف بین منابع 1 خلأ کیفیت
اختلاف بین منابع دیده شد

اختلاف‌ها مخفی نمی‌شوند و در شاخص اعتماد نیز اثر کاهشی دارند. پیش از تصمیم عملیاتی، مقدار هر منبع را بررسی کنید.

تاریخ انتشار
2026-06-152026-05-31
CISA Known Exploited Vulnerabilities رسمی
CVSS
—
شدت
—
محصول
—
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
—
CISA Known Exploited Vulnerabilities رسمی
CVSS
—
شدت
—
محصول
—
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
—
CISA Known Exploited Vulnerabilities رسمی
CVSS
—
شدت
—
محصول
—
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-06-15
LiteSpeed Security Blog رسمی
CVSS
—
شدت
high
محصول
LiteSpeed Technologies / LiteSpeed Products
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-05-31
NVD رسمی
CVSS
—
شدت
—
محصول
—
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
—
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
توضیحات 1 منبع
LiteSpeed Security Blogرسمی
LiteSpeed Blog / Products / LiteSpeed Web Server / Security Update for LiteSpeed cPanel Plugin Security Update for LiteSpeed cPanel Plugin June 1st, 2026 by Lisa Clarke LiteSpeed Web Server , Security 0 Comments We have another urgent security update for LiteSpeed’s user-end plugin for cPanel. Last night we were made aware of a vulnerability affecting our user-end cPanel plugin (LiteSpeed’s WHM...
منبع ↗
اثر 1 منبع
LiteSpeed Security Blogرسمی
A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.
منبع ↗
شدت 1 منبع
LiteSpeed Security Blogرسمی
high
منبع ↗
خلاصه 1 منبع
LiteSpeed Security Blogرسمی
A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.
منبع ↗
عنوان 1 منبع
LiteSpeed Security Blogرسمی
Security Update for LiteSpeed cPanel Plugin
منبع ↗
↗