Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2026-105314
- EPSS 0.9%
- Veröffentlicht 05.10.2026 07:28:30
- Zuletzt bearbeitet 06.10.2026 18:16:43
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
6.1
CVE-2020-29456
- EPSS 1.54%
- Veröffentlicht 02.12.2020 08:15:10
- Zuletzt bearbeitet 21.11.2024 05:24:02
Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document'...
1