Papercut Mf
Vendor:
First CVE: Apr 22, 2014 · Active for 12 years
29
Total CVEs
More Total CVEs than 97% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
10.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Papercut Mf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2014
12 years ago
Most Recent CVE
May 5, 2026
84 days ago
CVE Severity & Scoring
Papercut Mf29 CVEs
38%
41%
17%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (17.2%)
Network21 (72.4%)
Unknown3 (10.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (79.3%)
High3 (10.3%)
Unknown3 (10.3%)
User Interaction
None22 (75.9%)
Unknown3 (10.3%)
Required4 (13.8%)
Privileges Required
Low7 (24.1%)
High6 (20.7%)
None13 (44.8%)
Unknown3 (10.3%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27350CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu | Apr 20, 2023 | 9.8 | 99 | YES | YES |
CVE-2023-27351HIGH This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu | Apr 20, 2023 | 7.5 | 95 | YES | YES |
CVE-2023-39143CRITICAL PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when e | Aug 4, 2023 | 9.8 | 84 | NO | YES |
CVE-2023-2533HIGH A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
PaperCut NG/MF, which, under specific conditions, could potentially enable
an attacker to alter security se | Jun 20, 2023 | 8.8 | 80 | YES | NO |
CVE-2024-1222CRITICAL This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/M | Mar 14, 2024 | 9.8 | 65 | NO | NO |
CVE-2023-3486HIGH An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s fi | Jul 25, 2023 | 7.5 | 63 | NO | NO |
CVE-2023-39469HIGH PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 7.2 | 51 | NO | NO |
CVE-2024-1883MEDIUM This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a s | Mar 14, 2024 | 6.1 | 49 | NO | NO |
CVE-2024-1884MEDIUM This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requ | Mar 14, 2024 | 6.5 | 34 | NO | NO |
CVE-2019-8948CRITICAL PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. | Feb 20, 2019 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
3 CVEs
10.3% of CVEs· 98th percentile
Metasploit
1 CVE
3.4% of CVEs· 97th percentile
Nuclei
3 CVEs
10.3% of CVEs· 97th percentile
ExploitDB
1 CVE
3.4% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Papercut Mf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.1 | 1 | 7.5 | 1.1% | 0 | 0 |
| 14.0 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.5 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.4 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.3 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.2 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.1 | 2 | 5.9 | 1.0% | 0 | 0 |
| 13.0 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.5 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.4 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.3 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.2 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.1 | 2 | 5.9 | 1.0% | 0 | 0 |
| 12.0 | 2 | 5.9 | 1.0% | 0 | 0 |