CVE-2024-51915

WordPress LiteSpeed Cache plugin <= 6.5.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.2.


We have discovered 116,397 live websites that are affected by CVE-2024-51915.

Run a Free Instant Scan




Affected Software

Product  Litespeed Cache
Category Cache Tools
Vulnerable Domains116,397 live websites (13% of Litespeed Cache install base)
Vulnerable Versions
  • from 0 through 6.5.2
Vulnerable Versions Count126 versions ( 88% of all versions)



Details

  • Published - Feb 20, 2026
  • Updated - Apr 1, 2026

Credits

  • TaiYou | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2024-51915
United States30,840 websites



Poland7,278 websites
GB7,139 websites
Canada5,943 websites
Turkey5,809 websites
Germany4,559 websites
Spain4,488 websites
France4,453 websites
Romania4,092 websites
Vietnam3,536 websites

Website Distribution by TLD

Number of websites using CVE-2024-51915
.com51,301 websites
.pl5,412 websites
.org4,900 websites
.co.uk3,656 websites
.net3,312 websites
.com.br3,196 websites
.com.au1,917 websites
.ca1,914 websites
.nl1,885 websites
.es1,768 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-51915

Top websites that are affected by CVE-2024-51915. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.fm United States*,***
***********.com Austria*,***
***********.net United States**,***
****.org United States**,***
*******.com United States**,***
*********.com United States**,***
********.***.au Australia**,***
*********.com Germany**,***
******.com United States**,***
******.com Latvia**,***
See full domain list

FAQ

A total of 116,397 websites have been identified as vulnerable to CVE-2024-51915, based on global website indexing conducted by WebTechSurvey.
The Litespeed Cache is affected by the CVE-2024-51915 vulnerability.
Litespeed Cache versions up to and including 6.5.2 are vulnerable to CVE-2024-51915.