Known vulnerabilities in PaperCut MF

Software: PaperCut MF
Software CPE: cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
Total vulnerabilities: 24
Public exploits: 4
Known exploited (KEV): 7
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PaperCut MF PaperCut MF is affected by 24 known vulnerabilities: 5 critical, 3 high, 5 medium, 11 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146037 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE-2026-82078
CWE-470 Critical
No
Exploited
25.0.12, 26.0.4 28.08.2026 SB2026082828
#VU146038 - Missing Authentication for Critical Function
CVE-2026-81578
CWE-306 Critical
No
Exploited
25.0.12, 26.0.4 28.08.2026 SB2026082828
#VU97974 - Improper Access Control
CVE-2024-8405
CWE-284 Low
No
No
23.0.9 03.10.2024 SB2024061721
#VU97973 - Improper Access Control
CVE-2024-8404
CWE-284 Low
No
No
23.0.9 03.10.2024 SB2024061721
#VU92183 - Improper Access Control
CVE-2024-4712
CWE-284 Low
No
No
23.0.9 17.06.2024 SB2024061721
#VU92182 - Improper Access Control
CVE-2024-3037
CWE-284 Low
No
No
23.0.9 17.06.2024 SB2024061721
#VU87613 - Exposure of sensitive information to an unauthorized actor
CVE-2024-1221
CWE-200 Low
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87612 - Exposure of sensitive information to an unauthorized actor
CVE-2024-1223
CWE-200 Low
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87610 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-1883
CWE-79 Low
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87608 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-1882
CWE-94 Low
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87606 - Server-Side Request Forgery (SSRF)
CVE-2024-1884
CWE-918 Medium
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87600 - Permissions, Privileges, and Access Controls
CVE-2024-1654
CWE-264 Low
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU87599 - Improper Access Control
CVE-2024-1222
CWE-284 Medium
No
No
20.1.10, 21.2.14, 22.1.5, 23.0.7 19.03.2024 SB2024031917
#VU84492 - Untrusted Search Path
CVE-2023-6006
CWE-426 Low
No
No
23.0.1 18.12.2023 SB2023121811
#VU80183 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-39469
CWE-94 Low
No
No
22.1.1 31.08.2023 SB2023083117
#VU80182 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-31046
CWE-22 Medium
No
No
21.2.12, 22.1.1 31.08.2023 SB2023083117
#VU80181 - Cross-Site Request Forgery (CSRF)
CVE-2023-2533
CWE-352 Medium
Available
Exploited
20.1.8, 21.2.12, 22.1.1 31.08.2023 SB2023083117
#VU75419 - Improper Authentication
CVE-2023-27351
CWE-287 Critical
No
Exploited
20.1.7, 21.2.11, 22.0.9 24.04.2023 SB2023042401
#VU75418 - Improper Access Control
CVE-2023-27350
CWE-284 Critical
Available
Exploited
20.1.7, 21.2.11, 22.0.9 24.04.2023 SB2023042401
#VU74037 - Improper Access Control
CWE-284 High
No
No
20.1.7, 21.2.11, 22.0.9 27.03.2023 SB2023032713


Showing elements 1 - 20 out of 24