PaperCut / Papercut NG
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82078 KEV | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector | CRITICAL | 9.4 | Aug 28, 2026 |
| CVE-2026-81578 KEV | PaperCut MF/NG: Authentication Bypass | HIGH | 8.8 | Aug 28, 2026 |
| CVE-2026-6418 | PaperCut NG/MF: Path Traversal in Shared Account Synchronization | MEDIUM | 4.6 | May 5, 2026 |
| CVE-2026-6180 | PaperCut MF: Card truncation on HP readers | MEDIUM | 4.1 | May 5, 2026 |
| CVE-2026-4794 | Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF | LOW | 2.1 | Mar 31, 2026 |
| CVE-2024-9672 | Reflected XSS in PaperCut MF | MEDIUM | 6.3 | Dec 9, 2024 |
| CVE-2023-39470 | PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability | HIGH | 7.2 | Nov 22, 2024 |
| CVE-2024-8404 | Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder | HIGH | 7.8 | Sep 26, 2024 |
| CVE-2024-8405 | Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attack | MEDIUM | 6.1 | Sep 26, 2024 |
| CVE-2024-4712 | Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler | HIGH | 7.8 | May 14, 2024 |
| CVE-2024-3037 | Arbitrary File Deletion in PaperCut NG/MF Web Print | HIGH | 7.8 | May 14, 2024 |
| CVE-2023-39469 | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability | HIGH | 7.2 | May 3, 2024 |
| CVE-2024-1884 | Server Side Request Forgery in PaperCut NG/MF | MEDIUM | 6.5 | Mar 14, 2024 |
| CVE-2024-1883 | Reflected XSS in PaperCut NG/MF | MEDIUM | 6.3 | Mar 14, 2024 |
| CVE-2024-1882 | Server-side resource injection in PaperCut NG/MF | HIGH | 7.2 | Mar 14, 2024 |
| CVE-2024-1654 | Unauthorized write operations in PaperCut NG/MF | HIGH | 7.2 | Mar 14, 2024 |
| CVE-2024-1223 | Improper authorization controls in PaperCut NG/MF | MEDIUM | 4.8 | Mar 14, 2024 |
| CVE-2024-1222 | Incorrect authorization controls in PaperCut NG/MF APIs | CRITICAL | 9.8 | Mar 14, 2024 |
| CVE-2024-1221 | Improper access controls on APIs on Linux and macOS in PaperCut NG/MF | LOW | 3.1 | Mar 14, 2024 |
| CVE-2023-6006 | Privilege Escalation Vulnerability | HIGH | 7.8 | Nov 14, 2023 |
| CVE-2023-31046 | A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an au… | MEDIUM | 6.5 | Oct 19, 2023 |
| CVE-2023-4568 | PaperCut NG Unauthenticated XMLRPC | MEDIUM | 6.5 | Sep 13, 2023 |
| CVE-2023-39143 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote… | CRITICAL | 9.8 | Aug 4, 2023 |
| CVE-2023-3486 | PaperCut NG Unauthenticated File Upload | HIGH | 8.2 | Jul 25, 2023 |
| CVE-2023-2533 KEV | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF | HIGH | 8.8 | Jun 20, 2023 |
Showing 1 to 25 of 31 CVEs