VYPR
Vendor

Papercut

Products
9
CVEs
38
Across products
70
Status
Private

Products

9

Recent CVEs

38
View all 38 CVEs →
  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-27351HigKEVApr 20, 2023
    risk 0.73cvss 7.5epss 0.77

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results…

  • CVE-2023-39143CriAug 4, 2023
    risk 0.70cvss 9.8epss 0.80

    PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

  • CVE-2023-2533HigKEVJun 20, 2023
    risk 0.69cvss 8.4epss 0.29

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current…

  • CVE-2019-12135CriJun 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

  • CVE-2019-8948CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.04

    PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.

  • CVE-2024-1222HigMar 14, 2024
    risk 0.61cvss 8.6epss 0.64

    This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

  • CVE-2023-3486HigJul 25, 2023
    risk 0.59cvss 8.2epss 0.79

    An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as…

  • CVE-2022-47514HigDec 18, 2022
    risk 0.57cvss 8.8epss 0.01

    An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.

  • CVE-2026-6180HigMay 5, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence…

  • CVE-2024-8404HigSep 26, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2024-4712HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is…

  • CVE-2024-3037HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2023-39469HigMay 3, 2024
    risk 0.51cvss 7.2epss 0.58

    PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2023-6006HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system.…

  • CVE-2025-9785HigSep 3, 2025
    risk 0.50cvss epss 0.00

    PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the…

  • CVE-2026-5115HigMar 31, 2026
    risk 0.49cvss 7.5epss 0.00

    The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device. It was internally…

  • CVE-2026-6645HigJun 22, 2026
    risk 0.47cvss epss 0.00

    An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a…

  • CVE-2023-39470HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The…

  • CVE-2024-1882HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.01

    This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.