Browse all 5 CVE security advisories affecting papra-hq. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-48052 | Papra: Cross-organization tag deletion and modification via authenticated cross-tenant request — papra CWE-639 | 5.4 | Medium | 2026-07-27 |
| CVE-2026-48051 | Papra: SSRF via HTTP redirect bypass in webhook delivery — papra CWE-918 | 3.5 | Low | 2026-07-27 |
| CVE-2026-35462 | Papra Does Not Reject Expired API Keys — papra CWE-613 | 4.3 | Medium | 2026-04-07 |
| CVE-2026-35461 | Papra has a Blind Server-Side Request Forgery (SSRF) via Webhook URL — papra CWE-918 | 5.0 | Medium | 2026-04-07 |
| CVE-2026-35460 | Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name — papra CWE-80 | 4.3 | Medium | 2026-04-07 |
This page lists every published CVE security advisory associated with papra-hq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.