papercut records
34 published records for vendor papercut.
Researcher profile
- Entered KEV
- 5 · 14.7%
- Weaponized
- 5 · 14.7%
- Pre-auth RCE
- 5
- With a fix record
- 55.9%
- Median publish → KEV
- 3 days
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-76 Improper Neutralization of Equivalent Special Elements3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-287 Improper Authentication2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-27350Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Critical9.8 | KEV | 100.0% | Apr 20, 2023 |
83Now | CVE-2023-27351Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-287 | High7.5 | KEV | 78.1% | Apr 20, 2023 |
74This week | CVE-2023-2533Weaponized | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFpapercut · papercut mf · CWE-352 | High8.8 | KEV | 29.2% | Jun 20, 2023 |
68This week | CVE-2026-82078Weaponized | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connectorpapercut · papercut mf · CWE-470 | Critical9.4 | KEV | 3.8% | Aug 28, 2026 |
66This week | CVE-2026-81578Weaponized | PaperCut MF/NG: Authentication Bypasspapercut · papercut mf · CWE-305 | High8.8 | KEV | 4.5% | Aug 28, 2026 |
63This week | CVE-2023-39143Proof of concept | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.papercut · papercut mf · CWE-22 | Critical9.8 | — | 80.1% | Aug 4, 2023 |
58Plan | CVE-2024-1222No exploit | Incorrect authorization controls in PaperCut NG/MF APIspapercut · papercut mf · CWE-250 | Critical9.8 | — | 64.0% | Mar 13, 2024 |
54Plan | CVE-2023-3486No exploit | PaperCut NG Unauthenticated File Uploadpapercut · papercut mf · CWE-434 | High7.5 | — | 79.2% | Jul 25, 2023 |
46Plan | CVE-2023-39469No exploit | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerabilitypapercut · papercut mf · CWE-94 | High7.2 | — | 61.4% | May 2, 2024 |
42Plan | CVE-2024-1883No exploit | Reflected XSS in PaperCut NG/MFpapercut · papercut mf · CWE-76 | Medium6.1 | — | 61.5% | Mar 14, 2024 |
40Plan | CVE-2019-8948No exploit | PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.papercut · papercut mf · CWE-74 | Critical9.8 | — | 3.9% | Feb 20, 2019 |
40Plan | CVE-2019-12135No exploit | An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allpapercut · papercut mf | Critical9.8 | — | 2.5% | Jun 6, 2019 |
37Monitor | CVE-2024-1884No exploit | Server Side Request Forgery in PaperCut NG/MFpapercut · papercut mf · CWE-918 | Medium6.5 | — | 37.9% | Mar 14, 2024 |
31Monitor | CVE-2024-4712No exploit | Arbitrary File Creation in PaperCut NG/MF Web Print Image Handlerpapercut · papercut mf · CWE-77 | High7.8 | — | 0.4% | May 14, 2024 |
31Monitor | CVE-2024-3037No exploit | Arbitrary File Deletion in PaperCut NG/MF Web Printpapercut · papercut mf · CWE-59 | High7.8 | — | 0.4% | May 14, 2024 |
31Monitor | CVE-2024-8404No exploit | Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folderpapercut · papercut mf · CWE-59 | High7.8 | — | 0.4% | Sep 25, 2024 |
30Monitor | CVE-2014-2657No exploit | Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact and remote vectors,papercut · papercut mf | High7.5 | — | 1.1% | Apr 28, 2014 |
29Monitor | CVE-2023-39470No exploit | PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerabilitypapercut · papercut ng · CWE-749 | High7.2 | — | 1.8% | Nov 22, 2024 |
28Monitor | CVE-2024-1882No exploit | Server-side resource injection in PaperCut NG/MFpapercut · papercut mf · CWE-76 | High7.2 | — | 1.4% | Mar 14, 2024 |
28Monitor | CVE-2024-1654No exploit | Unauthorized write operations in PaperCut NG/MFpapercut · papercut mf · CWE-183 | High7.2 | — | 1.3% | Mar 13, 2024 |
27Monitor | CVE-2023-4568Proof of concept | PaperCut NG Unauthenticated XMLRPCpapercut · papercut ng · CWE-287 | Medium6.5 | — | 3.9% | Sep 13, 2023 |
27Monitor | CVE-2014-2659No exploit | Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hpapercut · papercut mf · CWE-352 | Medium6.8 | — | 0.6% | Apr 22, 2014 |
26Monitor | CVE-2023-31046No exploit | A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1.papercut · papercut mf · CWE-22 | Medium6.5 | — | 1.5% | Oct 19, 2023 |
26Monitor | CVE-2023-6006No exploit | Privilege Escalation Vulnerabilitypapercut · papercut mf · CWE-250 | Medium6.7 | — | 0.4% | Nov 14, 2023 |
26Monitor | CVE-2023-2508No exploit | CSRF in PaperCutNG Mobility Print leads to sophisticated phishingpapercut · mobility print server · CWE-352 | Medium6.5 | — | 0.3% | Sep 20, 2023 |
- CVE-2023-2735099Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%papercut · papercut mfApr 20, 2023
- CVE-2023-2735183Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
HighCVSS 7.5KEVWeaponizedEPSS 78%papercut · papercut mfApr 20, 2023
- CVE-2023-253374This week
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
HighCVSS 8.8KEVWeaponizedEPSS 29%papercut · papercut mfJun 20, 2023
- CVE-2026-8207868This week
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
CriticalCVSS 9.4KEVWeaponizedEPSS 4%papercut · papercut mfAug 28, 2026
- CVE-2026-8157866This week
PaperCut MF/NG: Authentication Bypass
HighCVSS 8.8KEVWeaponizedEPSS 4%papercut · papercut mfAug 28, 2026
- CVE-2023-3914363This week
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.
CriticalCVSS 9.8Proof of conceptEPSS 80%papercut · papercut mfAug 4, 2023
- CVE-2024-122258Plan
Incorrect authorization controls in PaperCut NG/MF APIs
CriticalCVSS 9.8No exploitEPSS 64%papercut · papercut mfMar 13, 2024
- CVE-2023-348654Plan
PaperCut NG Unauthenticated File Upload
HighCVSS 7.5No exploitEPSS 79%papercut · papercut mfJul 25, 2023
- CVE-2023-3946946Plan
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 61%papercut · papercut mfMay 2, 2024
- CVE-2024-188342Plan
Reflected XSS in PaperCut NG/MF
MediumCVSS 6.1No exploitEPSS 61%papercut · papercut mfMar 14, 2024
- CVE-2019-894840Plan
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
CriticalCVSS 9.8No exploitEPSS 4%papercut · papercut mfFeb 20, 2019
- CVE-2019-1213540Plan
An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier all
CriticalCVSS 9.8No exploitEPSS 2%papercut · papercut mfJun 6, 2019
- CVE-2024-188437Monitor
Server Side Request Forgery in PaperCut NG/MF
MediumCVSS 6.5No exploitEPSS 38%papercut · papercut mfMar 14, 2024
- CVE-2024-471231Monitor
Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler
HighCVSS 7.8No exploitEPSS 0%papercut · papercut mfMay 14, 2024
- CVE-2024-303731Monitor
Arbitrary File Deletion in PaperCut NG/MF Web Print
HighCVSS 7.8No exploitEPSS 0%papercut · papercut mfMay 14, 2024
- CVE-2024-840431Monitor
Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder
HighCVSS 7.8No exploitEPSS 0%papercut · papercut mfSep 25, 2024
- CVE-2014-265730Monitor
Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact and remote vectors,
HighCVSS 7.5No exploitEPSS 1%papercut · papercut mfApr 28, 2014
- CVE-2023-3947029Monitor
PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 2%papercut · papercut ngNov 22, 2024
- CVE-2024-188228Monitor
Server-side resource injection in PaperCut NG/MF
HighCVSS 7.2No exploitEPSS 1%papercut · papercut mfMar 14, 2024
- CVE-2024-165428Monitor
Unauthorized write operations in PaperCut NG/MF
HighCVSS 7.2No exploitEPSS 1%papercut · papercut mfMar 13, 2024
- CVE-2023-456827Monitor
PaperCut NG Unauthenticated XMLRPC
MediumCVSS 6.5Proof of conceptEPSS 4%papercut · papercut ngSep 13, 2023
- CVE-2014-265927Monitor
Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to h
MediumCVSS 6.8No exploitEPSS 1%papercut · papercut mfApr 22, 2014
- CVE-2023-3104626Monitor
A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1.
MediumCVSS 6.5No exploitEPSS 2%papercut · papercut mfOct 19, 2023
- CVE-2023-600626Monitor
Privilege Escalation Vulnerability
MediumCVSS 6.7No exploitEPSS 0%papercut · papercut mfNov 14, 2023
- CVE-2023-250826Monitor
CSRF in PaperCutNG Mobility Print leads to sophisticated phishing
MediumCVSS 6.5No exploitEPSS 0%papercut · mobility print serverSep 20, 2023