VYPR
Vendor

Papercut

Products
13
CVEs
44
Across products
80
Status
Private

Products

13

Recent CVEs

44
View all 44 CVEs →
  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-27351HigKEVApr 20, 2023
    risk 0.73cvss 7.5epss 0.78

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results…

  • CVE-2026-81578CriKEVAug 28, 2026
    risk 0.72cvss 9.8epss 0.04

    An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access…

  • CVE-2023-39143CriAug 4, 2023
    risk 0.70cvss 9.8epss 0.80

    PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

  • CVE-2023-2533HigKEVJun 20, 2023
    risk 0.69cvss 8.4epss 0.29

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current…

  • CVE-2026-82078CriKEVAug 28, 2026
    risk 0.67cvss 9.1epss 0.04

    An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an…

  • CVE-2019-12135CriJun 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

  • CVE-2019-8948CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.04

    PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.

  • CVE-2024-1222HigMar 14, 2024
    risk 0.61cvss 8.6epss 0.64

    This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

  • CVE-2023-3486HigJul 25, 2023
    risk 0.59cvss 8.2epss 0.79

    An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as…

  • CVE-2022-47514HigDec 18, 2022
    risk 0.57cvss 8.8epss 0.01

    An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.

  • CVE-2026-6180HigMay 5, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence…

  • CVE-2024-8404HigSep 26, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2024-4712HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is…

  • CVE-2024-3037HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2023-39469HigMay 3, 2024
    risk 0.51cvss 7.2epss 0.61

    PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2023-6006HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system.…

  • CVE-2025-9785HigSep 3, 2025
    risk 0.50cvss —epss 0.00

    PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the…

  • CVE-2026-14780HigSep 24, 2026
    risk 0.49cvss —epss 0.00

    A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a…

  • CVE-2026-5115HigMar 31, 2026
    risk 0.49cvss 7.5epss 0.00

    The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device. It was internally…