PaperCut Software develops print-management and document-control products deployed widely across educational institutions, enterprises, and managed-service-provider networks, where centralized print accounting and workflow automation create high-value targets. Despite a narrow product portfolio, the vendor is disproportionately represented in the vulnerability landscape, reflecting both the security-critical nature of print infrastructure and the long operational lifespans of many customer deployments. Vulnerabilities affecting PaperCut skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code; the vendor's disclosures have also attracted confirmed in-the-wild exploitation and cataloging by CISA. The exposure concentrates in its flagship products such as PaperCut MF and PaperCut NG, with recurring weaknesses in web-application request forgery, cross-site scripting, and input-neutralization flaws that reflect the web-facing administrative and user-portal attack surface common to centralized print-management platforms. Defenders should prioritize patches for this vendor given the combination of serious severity, exploit availability, and the critical role print infrastructure plays in many organizations; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by PaperCut Software Pty Ltd over time
Of all the CVEs published by PaperCut Software Pty Ltd as a CNA, 85.0% affect products that PaperCut Software Pty Ltd develops as a vendor.
Of all the CVEs published that affect products developed by PaperCut Software Pty Ltd, 53.1% are self-published by PaperCut Software Pty Ltd as a CNA.
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27350CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu | Apr 20, 2023 | 9.8 | 99 | YES | YES |
CVE-2023-27351HIGH This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu | Apr 20, 2023 | 7.5 | 95 | YES | YES |
CVE-2023-39143CRITICAL PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when e | Aug 4, 2023 | 9.8 | 84 | NO | YES |
CVE-2023-2533HIGH A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
PaperCut NG/MF, which, under specific conditions, could potentially enable
an attacker to alter security se | Jun 20, 2023 | 8.8 | 80 | YES | NO |
CVE-2024-1222CRITICAL This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/M | Mar 14, 2024 | 9.8 | 65 | NO | NO |
CVE-2023-3486HIGH An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s fi | Jul 25, 2023 | 7.5 | 61 | NO | NO |
CVE-2023-39469HIGH PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 7.2 | 51 | NO | NO |
CVE-2024-1883MEDIUM This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a s | Mar 14, 2024 | 6.1 | 49 | NO | NO |
CVE-2024-1884MEDIUM This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requ | Mar 14, 2024 | 6.5 | 34 | NO | NO |
CVE-2019-8948CRITICAL PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. | Feb 20, 2019 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by PaperCut Software Pty Ltd.
Media articles that mention a CVE ID that affects a product developed by PaperCut Software Pty Ltd — matched by CVE ID, not by vendor name.