Ether / Etherpad
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55086 | Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite | MEDIUM | 4.2 | Aug 19, 2026 |
| CVE-2026-55085 | Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite | CRITICAL | 9.6 | Aug 19, 2026 |
| CVE-2026-55089 | Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint | CRITICAL | 9.9 | Aug 19, 2026 |
| CVE-2026-55090 | Etherpad: Stored XSS in HTML export via unescaped attribute-pool values | HIGH | 8.7 | Aug 19, 2026 |
| CVE-2026-55088 | Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token | MEDIUM | 6.8 | Aug 19, 2026 |
| CVE-2026-55087 | Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) | MEDIUM | 6.1 | Aug 19, 2026 |
Showing 1 to 6 of 6 CVEs