Papercut Mf

Vendor:

First CVE: Apr 22, 2014 · Active for 12 years

29
Total CVEs
More Total CVEs than 97% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
10.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Papercut Mf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2014
12 years ago
Most Recent CVE
May 5, 2026
84 days ago

CVE Severity & Scoring

Papercut Mf29 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local5 (17.2%)
Network21 (72.4%)
Unknown3 (10.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (79.3%)
High3 (10.3%)
Unknown3 (10.3%)
User Interaction
None22 (75.9%)
Unknown3 (10.3%)
Required4 (13.8%)
Privileges Required
Low7 (24.1%)
High6 (20.7%)
None13 (44.8%)
Unknown3 (10.3%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu
Apr 20, 20239.899YESYES
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu
Apr 20, 20237.595YESYES
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when e
Aug 4, 20239.884NOYES
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security se
Jun 20, 20238.880YESNO
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/M
Mar 14, 20249.865NONO
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s fi
Jul 25, 20237.563NONO
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
May 3, 20247.251NONO
This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a s
Mar 14, 20246.149NONO
This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requ
Mar 14, 20246.534NONO
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
Feb 20, 20199.832NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
3 CVEs
10.3% of CVEs· 98th percentile
Metasploit
1 CVE
3.4% of CVEs· 97th percentile
Nuclei
3 CVEs
10.3% of CVEs· 97th percentile
ExploitDB
1 CVE
3.4% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Papercut Mf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.117.51.1%00
14.025.91.0%00
13.525.91.0%00
13.425.91.0%00
13.325.91.0%00
13.225.91.0%00
13.125.91.0%00
13.025.91.0%00
12.525.91.0%00
12.425.91.0%00
12.325.91.0%00
12.225.91.0%00
12.125.91.0%00
12.025.91.0%00