Etherpad is a widely deployed collaborative document-editing platform with a narrowly scoped but prominently embedded product footprint across web-based and real-time-editing use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability, while recurring weakness classes—including improper input validation, path traversal, cross-site scripting, and sensitive-information exposure—reflect the parsing and sanitization demands of a browser-based collaboration tool. Defenders should treat Etherpad instances as internet-facing assets requiring prompt patching; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etherpad over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9845CRITICAL Etherpad Lite before 1.6.4 is exploitable for admin access. | Apr 29, 2018 | 9.8 | 48 | NO | YES |
CVE-2018-6835CRITICAL node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions. | Feb 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-9326CRITICAL Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. | Apr 7, 2018 | 9.8 | 30 | NO | NO |
CVE-2021-43802HIGH Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin pr | Dec 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-9327HIGH Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, Mo | Apr 7, 2018 | 8.1 | 26 | NO | NO |
CVE-2021-34816HIGH An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-contr | Jul 21, 2021 | 7.2 | 24 | NO | NO |
CVE-2020-22782HIGH Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance. | Apr 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-22781HIGH In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). | Apr 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-9325HIGH Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names. | Apr 7, 2018 | 7.5 | 23 | NO | NO |
CVE-2020-22784HIGH In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could a | Apr 28, 2021 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etherpad.
Media articles that mention a CVE ID that affects a product developed by Etherpad — matched by CVE ID, not by vendor name.