Vendors9001copypartyany version
Vulnerabilities

9001 Copyparty any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-37474
Path traversal in copyparty
Published 2023-07-14 · Modified
7.5EPSS 0.449
CVE-2025-54796
Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page
Published 2025-08-01 · Analyzed
7.5EPSS 0.004
CVE-2025-58753
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Published 2025-09-09 · Analyzed
7.5EPSS 0.004
CVE-2026-32108
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
Published 2026-03-11 · Analyzed
6.5EPSS 0.003
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
Published 2023-07-25 · Modified
6.31 PoCEPSS 0.092
CVE-2025-54589
copyparty Reflected XSS via Filter Parameter
Published 2025-07-31 · Analyzed
6.31 PoCEPSS 0.024
CVE-2025-27145
copyparty renders unsanitized filenames as HTML when user uploads empty files
Published 2025-02-25 · Analyzed
6.1EPSS 0.005
CVE-2025-54423
copyparty has a DOM-Based XSS vulnerability when displaying multimedia metadata
Published 2025-07-28 · Analyzed
6.1EPSS 0.004
CVE-2026-27948
Copyparty vulnerable to eflected cross-site scripting via setck parameter
Published 2026-02-26 · Analyzed
6.1EPSS 0.003
CVE-2026-30974
Copyparty volflag `nohtml` did not block javascript in svg files
Published 2026-03-10 · Analyzed
5.4EPSS 0.003
CVE-2026-32109
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
Published 2026-03-11 · Analyzed
4.4EPSS 0.002