CVE-2023-40000

HIGH EXPLOITED NUCLEI

Litespeedtech Litespeed Cache < 5.7.0.1 - XSS

Title source: rule

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

Exploits (3)

nomisec SCANNER 7 stars
by rxerium · infoleak
https://github.com/rxerium/CVE-2023-40000
nomisec WORKING POC 5 stars
by quantiom · client-side
https://github.com/quantiom/litespeed-cache-xss-poc
nomisec WORKING POC 1 stars
by iveresk · client-side
https://github.com/iveresk/cve-2023-40000

Nuclei Templates (1)

LiteSpeed Cache <= 5.7 - Unauthenticated Stored XSS
HIGHVERIFIEDby 0x_Akoko
Shodan: vuln:CVE-2023-40000
FOFA: wp-content/plugins/litespeed-cache/

Scores

CVSS v3 8.3
EPSS 0.8203
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Details

VulnCheck KEV 2024-05-03
CWE
CWE-79
Status published
Products (1)
litespeedtech/litespeed_cache < 5.7.0.1
Published Apr 16, 2024
Tracked Since Feb 18, 2026