vciy

CVEs we hold for Papercut

Records whose assigning authority named Papercut as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8794PaperCut NG/MF: User enumeration via timing attackPaperCut NG/MF
CVE-2026-8793PaperCut NG/MF: Insufficient brute-force protectionPaperCut NG/MF
CVE-2026-82078PaperCut MF/NG: Unsafe Dynamic Class Loading in Database ConnectorPaperCut MF/NG
CVE-2026-81578PaperCut MF/NG: Authentication BypassPaperCut MF/NG
CVE-2026-7824PaperCut Hive (Ricoh): Plain text password in logsPaperCut Hive
CVE-2026-6645Insecure Search Path Vulnerability in PaperCut Print Deploy Client for WindowsPaperCut Print Deploy
CVE-2026-6418PaperCut NG/MF: Path Traversal in Shared Account SynchronizationPaperCut NG/MF
CVE-2026-6180PaperCut MF: Card truncation on HP readersPaperCut NG/MF
CVE-2026-5115Session hijacking in PaperCut NG/MF embedded application for Konica Minolta devicesPapercut NG/MF
CVE-2026-4794Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MFPaperCut NG/MF
CVE-2025-9785Misconfigured certificate validation with self-signed certificates for Print DeployPaperCut Print Deploy
CVE-2024-9672Reflected XSS in PaperCut MFPaperCut MF
CVE-2024-8405Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attackPaperCut MF
CVE-2024-8404Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folderPaperCut MF
CVE-2024-4712Arbitrary File Creation in PaperCut NG/MF Web Print Image HandlerPaperCut MF
CVE-2024-3037Arbitrary File Deletion in PaperCut NG/MF Web PrintPaperCut MF
CVE-2024-1884Server Side Request Forgery in PaperCut NG/MFPaperCut MF
CVE-2024-1883Reflected XSS in PaperCut NG/MFPaperCut MF
CVE-2024-1882Server-side resource injection in PaperCut NG/MFPaperCut MF
CVE-2024-1654Unauthorized write operations in PaperCut NG/MFPaperCut MF
CVE-2024-1223Improper authorization controls in PaperCut NG/MFPaperCut MF
CVE-2024-1222Incorrect authorization controls in PaperCut NG/MF APIsPaperCut MF
CVE-2024-1221Improper access controls on APIs on Linux and macOS in PaperCut NG/MFPaperCut MF
CVE-2023-6006Privilege Escalation VulnerabilityPaperCut MF
CVE-2023-4568PaperCut NG Unauthenticated XMLRPCPaperCut NG
CVE-2023-39470PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution VulnerabilityPaperCut NG
CVE-2023-39469PaperCut NG External User Lookup Code Injection Remote Code Execution VulnerabilityPaperCut NG
CVE-2023-3486PaperCut NG Unauthenticated File UploadPaperCut NG
CVE-2023-27351no title heldPaperCut NG
CVE-2023-27350no title heldPaperCut NG
CVE-2023-2533PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFPaperCut NG/MF
CVE-2023-2508CSRF in PaperCutNG Mobility Print leads to sophisticated phishingPaperCut MF/NG Mobility Print

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.