Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Copyparty MEDIUM 6.5
CVE-2026-32108

Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulne…

Fix: 1.20.12+
Fix from $1,600 2026-03-11
Copyparty MEDIUM 5.4
CVE-2026-30974

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML …

Fix: 1.20.11+
Fix from $1,600 2026-03-10
Copyparty MEDIUM 6.1
CVE-2026-27948

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Ve…

Fix: 1.20.9+
Fix from $1,600 2026-02-26
Copyparty HIGH 7.5
CVE-2025-58753

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option…

Fix: 1.19.8+
Fix from $1,950 2025-09-09
Copyparty HIGH 7.8
CVE-2023-41471

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-P…

No fix yet
Fix from $1,950 2025-08-29
Copyparty HIGH 7.5
CVE-2025-54796

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this f…

Fix: 1.18.9+
Fix from $1,950 2025-08-02
Copyparty MEDIUM 6.1
CVE-2025-54589

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usi…

Fix: 1.18.7+
Fix from $1,600 2025-07-31
Copyparty MEDIUM 6.1
CVE-2025-54423

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaSc…

Fix: 1.18.5+
Fix from $1,600 2025-07-28
Copyparty MEDIUM 6.1
CVE-2025-27145

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered l…

Fix: 1.16.15+
Fix from $1,600 2025-02-25
Copyparty MEDIUM 6.1
CVE-2023-38501EPSS 9%

copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` an…

Fix: 1.8.7+
Fix from $1,600 2023-07-25
Copyparty HIGH 7.5
CVE-2023-37474EPSS 45%

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path…

Fix: 1.8.2+
Fix from $1,950 2023-07-14