Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.7
CVE-2026-57957
- EPSS 0.25%
- Veröffentlicht 29.06.2026 17:23:10
- Zuletzt bearbeitet 14.07.2026 22:17:25
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint refl...
6.5
CVE-2025-57682
- EPSS 0.65%
- Veröffentlicht 22.09.2025 00:00:00
- Zuletzt bearbeitet 14.10.2025 19:56:26
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API
1