Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

copyparty — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in copyparty, with AI-generated Chinese analysis, references, and POCs.

Vendor: 9001

CVE ID Title CVSS Severity Published
CVE-2026-93353 copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers CWE-59 3.1 Low 2026-09-24
CVE-2026-70657 Copyparty: file/dirkey confusion CWE-863 4.3 Medium 2026-08-18
CVE-2026-32109 Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html` CWE-79 3.7 Low 2026-03-11
CVE-2026-32108 Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access CWE-863 7.5AI High AI 2026-03-11
CVE-2026-30974 Copyparty volflag `nohtml` did not block javascript in svg files CWE-79 4.6 Medium 2026-03-10
CVE-2026-27948 Copyparty vulnerable to eflected cross-site scripting via setck parameter CWE-79 5.4 Medium 2026-02-26
CVE-2025-58753 copyparty: Sharing a single file does not fully restrict access to other files in source folder CWE-862 5.3AI Medium AI 2025-09-09
CVE-2025-54796 Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page CWE-400 7.5 High 2025-08-01
CVE-2025-54589 copyparty Reflected XSS via Filter Parameter CWE-79 6.3 Medium 2025-07-31
CVE-2025-54423 copyparty has a DOM-Based XSS vulnerability when displaying multimedia metadata CWE-79 5.4 Medium 2025-07-28
CVE-2025-27145 copyparty renders unsanitized filenames as HTML when user uploads empty files CWE-83 3.6 Low 2025-02-25
CVE-2023-38501 copyparty vulnerable to reflected cross-site scripting via k304 parameter CWE-79 6.3 Medium 2023-07-25
CVE-2023-37474 Path traversal in copyparty CWE-22 9.8 - 2023-07-14

All 13 known CVE vulnerabilities affecting copyparty with full Chinese analysis, references, and POCs where available.