Skip to main content

Vendor/product archive

9001 / copyparty CVEs

Beta · best-effort

12 CVEs tagged to 9001 / copyparty0 Critical, 3 High, 6 Medium, 3 Low, 0 Unrated.

CVE-2026-32109

Published Mar 11, 2026

Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to the server, they can upload a malicious file with the file…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32108

Published Mar 11, 2026

Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30974

Published Mar 10, 2026

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG im…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-27948

Published Feb 26, 2026

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-58753

Published Sep 9, 2025

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created fo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41471

Published Aug 29, 2025

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is d…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54796

Published Aug 2, 2025

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54589

Published Jul 31, 2025

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54423

Published Jul 28, 2025

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browse…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27145

Published Feb 25, 2025

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38501

Published Jul 25, 2023

copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37474

Published Jul 14, 2023

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1