9001 develops copyparty, a file-sharing and media-serving application whose vulnerability profile centers on web-tier input handling and access-control weaknesses. The vendor's disclosures cluster around cross-site scripting, path-traversal, and improper file-access issues typical of user-facing web applications, and public exploit code has been developed for vulnerabilities in this product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 9001 over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37474HIGH Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique all | Jul 14, 2023 | 7.5 | 56 | NO | YES |
CVE-2025-54589MEDIUM Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. T | Jul 31, 2025 | 6.1 | 41 | NO | YES |
CVE-2023-38501MEDIUM copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case | Jul 25, 2023 | 6.1 | 38 | NO | YES |
CVE-2025-58753HIGH Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for | Sep 9, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54796HIGH Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the | Aug 2, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-41471HIGH Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is di | Aug 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2026-32108MEDIUM Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-27948MEDIUM Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue. | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-54423MEDIUM copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser | Jul 28, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-30974MEDIUM Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG ima | Mar 10, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 9001.
Media articles that mention a CVE ID that affects a product developed by 9001 — matched by CVE ID, not by vendor name.