Copyparty
Vendor:
First CVE: Jul 14, 2023 · Active for 3 years
12
Total CVEs
More Total CVEs than 91% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Copyparty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2023
3 years ago
Most Recent CVE
Mar 11, 2026
139 days ago
CVE Severity & Scoring
Copyparty12 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None9 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37474HIGH Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique all | Jul 14, 2023 | 7.5 | 56 | NO | YES |
CVE-2025-54589MEDIUM Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. T | Jul 31, 2025 | 6.1 | 41 | NO | YES |
CVE-2023-38501MEDIUM copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case | Jul 25, 2023 | 6.1 | 40 | NO | YES |
CVE-2025-58753HIGH Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for | Sep 9, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54796HIGH Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the | Aug 2, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-41471HIGH Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is di | Aug 29, 2025 | 7.8 | 24 | NO | NO |
CVE-2026-32108MEDIUM Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-27948MEDIUM Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue. | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-54423MEDIUM copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser | Jul 28, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-30974MEDIUM Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG ima | Mar 10, 2026 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
25.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
16.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Copyparty
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.1 | 1 | 7.8 | 0.2% | 0 | 0 |