CVE-2021-47855 MEDIUM

CVE-2021-47855: Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting

Vendor Litespeed Technologies
Product OpenLiteSpeed
Weakness CWE-79 · XSS
Published January 21, 2026
Last update March 5, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.

Key dates

02Disclosure timeline

January 21, 2026 CVE published
March 5, 2026 Record updated