Skip to main content

Vendor archive

papercut CVEs

Beta · best-effort

32 CVEs tagged to vendor papercut4 Critical, 13 High, 12 Medium, 3 Low, 0 Unrated.

CVE-2026-6418

Published May 5, 2026

An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6180

Published May 5, 2026

A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4794

Published Mar 31, 2026

Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via differ…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39470

Published Nov 22, 2024

PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8405

Published Sep 26, 2024

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe proc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8404

Published Sep 26, 2024

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must f…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39469

Published May 3, 2024

PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31046

Published Oct 19, 2023

A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an authenticated attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4568

Published Sep 13, 2023

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3486

Published Jul 25, 2023

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s f…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2533

Published Jun 20, 2023

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security s…

CVSS 8.4 · High
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2