All 6 CVE vulnerabilities found in DMS, with AI-generated Chinese analysis, references, and POCs.
Vendor: Papermerge
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-41879 | Weak password hashing in R-SOFT DMS CWE-328 | - | - | 2026-07-10 |
| CVE-2026-41878 | Insecure Direct Object Reference in R-SOFT DMS CWE-639 | - | - | 2026-07-10 |
| CVE-2026-41880 | OS Command Injection in R-SOFT DMS CWE-78 | - | - | 2026-07-10 |
| CVE-2026-41877 | Stored XSS in R-SOFT DMS CWE-79 | - | - | 2026-07-10 |
| CVE-2026-41876 | OS Command Injection in R-SOFT DMS CWE-78 | - | - | 2026-07-10 |
| CVE-2025-10209 | Papermerge DMS Authorization Token improper authorization CWE-285 | 5.4 | Medium | 2025-09-10 |
All 6 known CVE vulnerabilities affecting DMS with full Chinese analysis, references, and POCs where available.