Papermark is a document-sharing and collaboration platform with a focused product scope centered on its core Papermark application. Its disclosed vulnerability profile reflects path-traversal issues that are characteristic of file-handling logic in web-based document services, where proper access control to restricted directories is critical to maintaining confidentiality. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Papermark over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57957MEDIUM Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-o | Jun 29, 2026 | 4.7 | 26 | NO | NO |
CVE-2025-57682MEDIUM Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via | Sep 22, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Papermark.
Media articles that mention a CVE ID that affects a product developed by Papermark — matched by CVE ID, not by vendor name.