VendorsPaperCutpapercut_mfany version
Vulnerabilities

PaperCut Papercut Mf any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
Published 2023-04-20 · Analyzed
9.8KEV2 PoCEPSS 1.000
CVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
Published 2023-08-04 · Modified
9.8EPSS 0.801
CVE-2024-1222
Incorrect authorization controls in PaperCut NG/MF APIs
Published 2024-03-14 · Analyzed
9.8EPSS 0.640
CVE-2026-81578
PaperCut MF/NG: Authentication Bypass
Published 2026-08-28 · Analyzed
9.8KEVEPSS 0.045
CVE-2019-8948
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
Published 2019-02-20 · Modified
9.8EPSS 0.039
CVE-2019-12135
An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.
Published 2019-06-06 · Modified
9.8EPSS 0.025
CVE-2026-82078
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
Published 2026-08-28 · Analyzed
9.4KEVEPSS 0.038
CVE-2023-2533
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
Published 2023-06-20 · Analyzed
8.8KEVEPSS 0.292
CVE-2023-3486
PaperCut NG Unauthenticated File Upload
Published 2023-07-25 · Modified
8.2EPSS 0.792
CVE-2023-27351
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.
Published 2023-04-20 · Analyzed
8.2KEVEPSS 0.781
CVE-2026-6180
PaperCut MF: Card truncation on HP readers
Published 2026-05-05 · Analyzed
8.1EPSS 0.004
CVE-2024-4712
Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler
Published 2024-05-14 · Analyzed
7.8EPSS 0.004
CVE-2024-3037
Arbitrary File Deletion in PaperCut NG/MF Web Print
Published 2024-05-14 · Analyzed
7.8EPSS 0.004
CVE-2024-8404
Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder
Published 2024-09-26 · Modified
7.8EPSS 0.004
CVE-2023-6006
Privilege Escalation Vulnerability
Published 2023-11-14 · Modified
7.8EPSS 0.004
CVE-2026-5115
Session hijacking in PaperCut NG/MF embedded application for Konica Minolta devices
Published 2026-03-31 · Analyzed
7.5EPSS 0.003
CVE-2023-39469
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.2EPSS 0.614
CVE-2024-1882
Server-side resource injection in PaperCut NG/MF
Published 2024-03-14 · Analyzed
7.2EPSS 0.014
CVE-2024-1654
Unauthorized write operations in PaperCut NG/MF
Published 2024-03-14 · Analyzed
7.2EPSS 0.013
CVE-2014-2659
Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published 2014-04-22 · Modified
6.8EPSS 0.006
CVE-2024-1884
Server Side Request Forgery in PaperCut NG/MF
Published 2024-03-14 · Analyzed
6.5EPSS 0.379
CVE-2023-31046
A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an authenticated attacker to achieve read-only access to the server's filesystem, because requests beginning with "GET /ui/static/..//.." reach getStaticContent in UIContentResource.class in the static-content-files servlet.
Published 2023-10-19 · Modified
6.5EPSS 0.015
CVE-2024-1883
Reflected XSS in PaperCut NG/MF
Published 2024-03-14 · Analyzed
6.3EPSS 0.615
CVE-2024-9672
Reflected XSS in PaperCut MF
Published 2024-12-09 · Analyzed
6.3EPSS 0.002
CVE-2024-8405
Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attack
Published 2024-09-26 · Analyzed
6.1EPSS 0.002
CVE-2014-2658
Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service via unknown vectors.
Published 2014-04-28 · Modified
5.0EPSS 0.014
CVE-2026-6418
PaperCut NG/MF: Path Traversal in Shared Account Synchronization
Published 2026-05-05 · Analyzed
4.9EPSS 0.006
CVE-2024-1223
Improper authorization controls in PaperCut NG/MF
Published 2024-03-14 · Analyzed
4.8EPSS 0.004
CVE-2026-4794
Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF
Published 2026-03-31 · Analyzed
4.8EPSS 0.002
CVE-2024-1221
Improper access controls on APIs on Linux and macOS in PaperCut NG/MF
Published 2024-03-14 · Analyzed
3.1EPSS 0.005