CVE-2026-32109
- EPSS 0.01%
- Veröffentlicht 11.03.2026 20:16:34
- Zuletzt bearbeitet 13.03.2026 15:51:01
Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to the server, they can upload a malicious file with the filename .prologue.html and then craft a link to potentially execute arbitr...
CVE-2026-32108
- EPSS 0.01%
- Veröffentlicht 11.03.2026 20:14:18
- Zuletzt bearbeitet 13.03.2026 15:51:26
Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the shares feature is used for the specific purpose of creating a share of...
CVE-2026-30974
- EPSS 0.04%
- Veröffentlicht 10.03.2026 17:37:26
- Zuletzt bearbeitet 13.03.2026 20:14:44
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embed...
CVE-2026-27948
- EPSS 0.04%
- Veröffentlicht 26.02.2026 01:32:15
- Zuletzt bearbeitet 28.02.2026 00:56:59
Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.
CVE-2025-58753
- EPSS 0.02%
- Veröffentlicht 09.09.2025 19:54:36
- Zuletzt bearbeitet 18.09.2025 17:35:49
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for just one file inside a folder, it was possible to access the other fi...
CVE-2023-41471
- EPSS 0.03%
- Veröffentlicht 29.08.2025 00:00:00
- Zuletzt bearbeitet 03.11.2025 06:15:33
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already ...
CVE-2025-54796
- EPSS 0.07%
- Veröffentlicht 01.08.2025 23:38:27
- Zuletzt bearbeitet 12.09.2025 16:13:54
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. ...
CVE-2025-54589
- EPSS 0.62%
- Veröffentlicht 31.07.2025 13:48:41
- Zuletzt bearbeitet 22.09.2025 14:38:17
Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its va...
CVE-2025-54423
- EPSS 0.07%
- Veröffentlicht 28.07.2025 19:53:24
- Zuletzt bearbeitet 22.09.2025 14:39:06
copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of multimedia tags in music files, inclu...
CVE-2025-27145
- EPSS 0.3%
- Veröffentlicht 25.02.2025 02:15:16
- Zuletzt bearbeitet 19.09.2025 19:06:29
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging the file i...