Vendors9001copypartyall versions
Vulnerabilities

9001 Copyparty

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2023-41471
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript.
Published 2025-08-29 · Modified
7.8EPSS 0.003
CVE-2023-37474
Path traversal in copyparty
Published 2023-07-14 · Modified
7.5EPSS 0.449
CVE-2025-54796
Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page
Published 2025-08-01 · Analyzed
7.5EPSS 0.004
CVE-2025-58753
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Published 2025-09-09 · Analyzed
7.5EPSS 0.004
CVE-2026-32108
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
Published 2026-03-11 · Analyzed
6.5EPSS 0.003
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
Published 2023-07-25 · Modified
6.31 PoCEPSS 0.092
CVE-2025-54589
copyparty Reflected XSS via Filter Parameter
Published 2025-07-31 · Analyzed
6.31 PoCEPSS 0.024
CVE-2025-27145
copyparty renders unsanitized filenames as HTML when user uploads empty files
Published 2025-02-25 · Analyzed
6.1EPSS 0.005
CVE-2025-54423
copyparty has a DOM-Based XSS vulnerability when displaying multimedia metadata
Published 2025-07-28 · Analyzed
6.1EPSS 0.004
CVE-2026-27948
Copyparty vulnerable to eflected cross-site scripting via setck parameter
Published 2026-02-26 · Analyzed
6.1EPSS 0.003
CVE-2026-30974
Copyparty volflag `nohtml` did not block javascript in svg files
Published 2026-03-10 · Analyzed
5.4EPSS 0.003
CVE-2026-32109
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
Published 2026-03-11 · Analyzed
4.4EPSS 0.002