CVE-2025-58753
- EPSS 0.04%
- Published 09.09.2025 19:54:36
- Last modified 18.09.2025 17:35:49
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for just one file inside a folder, it was possible to access the other fi...
CVE-2023-41471
- EPSS 0.02%
- Published 29.08.2025 00:00:00
- Last modified 09.09.2025 13:35:53
Cross Site Scripting vulnerability in copyparty v.1.9.1 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function.
CVE-2025-54796
- EPSS 0.07%
- Published 01.08.2025 23:38:27
- Last modified 12.09.2025 16:13:54
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. ...
CVE-2025-54589
- EPSS 1.43%
- Published 31.07.2025 13:48:41
- Last modified 22.09.2025 14:38:17
Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its va...
CVE-2025-54423
- EPSS 0.09%
- Published 28.07.2025 19:53:24
- Last modified 22.09.2025 14:39:06
copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of multimedia tags in music files, inclu...
CVE-2025-27145
- EPSS 0.04%
- Published 25.02.2025 02:15:16
- Last modified 19.09.2025 19:06:29
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging the file i...
CVE-2023-38501
- EPSS 66.83%
- Published 25.07.2023 22:15:10
- Last modified 04.09.2025 13:04:46
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the ...
CVE-2023-37474
- EPSS 89.93%
- Published 14.07.2023 20:15:09
- Last modified 04.09.2025 13:04:46
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside...