OVERVIEW Papra versions prior to 26.4.0 contain a stored cross-site scripting vulnerability in transactional email templates. The application fails to escape or sanitize the user.name field when generating verification and password reset emails, allowing attackers to inject arbitrary HTML tags through their display name during account registration. SEVERITY This vulnerability carries a CVSS 3.1 score of 4.3 (Medium) with a network attack vector requiring low complexity and user authentication. The impact is limited to integrity compromise with no confidentiality or availability impact. The attack exploits the trust users place in legitimate email domains, enabling convincing phishing campaigns that masquerade as official Papra communications. The FAUCET Risk Score of 30.0 reflects moderate concern within the threat landscape. EXPLOITATION STATUS There is no indication of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog and remains on the KEV Inactive List. The extremely low EPSS score of 0.00034 indicates minimal probability of exploitation in the wild. This suggests low community attention and no readily available proof-of-concept code, though the simplicity of the attack vector means exploitation remains straightforward for motivated threat actors. Organizations should prioritize upgrading to version 26.4.0 to remediate this email-based phishing vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.4.0CPE matchmatch criteria | cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.