Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PaperCut — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting PaperCut. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PaperCut is a widely deployed print management solution that centralizes control over printing, scanning, and copying workflows across enterprise environments. Its architecture, which integrates deeply with existing network infrastructure, has historically exposed it to diverse security flaws. Recorded vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure default configurations in its web interface and API endpoints. These issues allow attackers to potentially gain unauthorized access to sensitive document data or disrupt critical office operations. While the vendor actively releases patches, the sheer volume of twenty-six Common Vulnerabilities and Exposures highlights the complexity of securing such integrated systems. Organizations must prioritize timely updates and strict access controls to mitigate risks associated with these known weaknesses, ensuring that the convenience of centralized print management does not compromise overall network integrity.

CVE ID Title CVSS Severity Published
CVE-2026-11744 PaperCut Hive Embedded App for Ricoh: Javascript injection — PaperCut Hive CWE-79 3.8 Low 2026-09-24
CVE-2026-87739 PaperCut MF/NG: User permissions are not evaluated on report generation — PaperCut NG/MF CWE-639 6.9 Medium 2026-09-24
CVE-2026-82077 PaperCut NG/MF: Remote Code Execution via Scan2Fax — PaperCut NG/MF CWE-22 7.3 High 2026-09-24
CVE-2026-14780 PaperCut NG/MF: Remote Code Execution via Scripting Subsystem — PaperCut NG/MF CWE-94 7.5 High 2026-09-24
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector — PaperCut MF/NG CWE-470 9.4 Critical 2026-08-28
CVE-2026-81578 PaperCut MF/NG: Authentication Bypass — PaperCut MF/NG CWE-305 8.8 High 2026-08-28
CVE-2026-8794 PaperCut NG/MF: User enumeration via timing attack — PaperCut NG/MF CWE-208 6.9 Medium 2026-08-03
CVE-2026-8793 PaperCut NG/MF: Insufficient brute-force protection — PaperCut NG/MF CWE-307 6.9 Medium 2026-08-03
CVE-2026-6645 Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows — Print Deploy CWE-427 - - 2026-06-22
CVE-2026-7824 PaperCut Hive (Ricoh): Plain text password in logs — PaperCut Hive CWE-532 6.5 - 2026-05-05
CVE-2026-6418 PaperCut NG/MF: Path Traversal in Shared Account Synchronization — PaperCut NG/MF CWE-36 2.7 - 2026-05-05
CVE-2026-6180 PaperCut MF: Card truncation on HP readers — PaperCut NG/MF CWE-367 3.7 - 2026-05-05
CVE-2026-5115 Session hijacking in PaperCut NG/MF embedded application for Konica Minolta devices — Papercut NG/MF CWE-319 7.1AI High AI 2026-03-31
CVE-2026-4794 Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF — PaperCut NG/MF CWE-79 4.8AI Medium AI 2026-03-31
CVE-2025-9785 Misconfigured certificate validation with self-signed certificates for Print Deploy — Print Deploy CWE-295 7.4AI High AI 2025-09-03
CVE-2024-9672 Reflected XSS in PaperCut MF — PaperCut MF CWE-917 6.1 - 2024-12-09
CVE-2023-39470 PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability — NG CWE-749 8.8 - 2024-11-22
CVE-2024-8404 Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder — PaperCut NG, PaperCut MF CWE-59 7.8 High 2024-09-26
CVE-2024-8405 Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attack — PaperCut NG, PaperCut MF CWE-77 6.1 Medium 2024-09-26
CVE-2024-4712 Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler — PaperCut NG, PaperCut MF CWE-77 7.8 High 2024-05-14
CVE-2024-3037 Arbitrary File Deletion in PaperCut NG/MF Web Print — PaperCut NG, PaperCut MF CWE-59 7.8 High 2024-05-14
CVE-2023-39469 PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability — NG CWE-94 8.8 - 2024-05-03
CVE-2024-1884 Server Side Request Forgery in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-918 6.5 Medium 2024-03-14
CVE-2024-1883 Reflected XSS in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-76 6.3 Medium 2024-03-14
CVE-2024-1882 Server-side resource injection in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-76 7.2 High 2024-03-14
CVE-2024-1654 Unauthorized write operations in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-183 7.2 High 2024-03-14
CVE-2024-1223 Improper authorization controls in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-488 4.8 Medium 2024-03-14
CVE-2024-1222 Incorrect authorization controls in PaperCut NG/MF APIs — PaperCut NG, PaperCut MF CWE-250 8.6 High 2024-03-14
CVE-2024-1221 Improper access controls on APIs on Linux and macOS in PaperCut NG/MF — PaperCut NG, PaperCut MF CWE-76 3.1 Low 2024-03-14
CVE-2023-6006 Privilege Escalation Vulnerability — PaperCut NG, PaperCut MF CWE-250 7.8 High 2023-11-14

This page lists every published CVE security advisory associated with PaperCut. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.