Paperthin's vulnerability footprint centers on the CommonSpot Content Server, a web-based content-management platform whose exposure recurs through application-layer input-handling and information-disclosure weaknesses including cross-site scripting, code injection, path traversal, and sensitive data exposure. While the vendor's product scope is narrow, this content server sits as a trusted component in publishing and web-management workflows, making its disclosures relevant to organizations running that platform. Public exploit code has been associated with vulnerabilities in this product class, underscoring the importance of timely patching; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paperthin over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2874HIGH PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context. | Apr 15, 2014 | 10.0 | 31 | NO | NO |
CVE-2014-2867HIGH Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page, a | Apr 15, 2014 | 10.0 | 26 | NO | NO |
CVE-2014-2864HIGH Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter | Apr 15, 2014 | 10.0 | 26 | NO | NO |
CVE-2014-2863HIGH Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname | Apr 15, 2014 | 10.0 | 26 | NO | NO |
CVE-2014-2866HIGH PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by | Apr 15, 2014 | 10.0 | 25 | NO | NO |
CVE-2014-2859HIGH PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request. | Apr 15, 2014 | 7.5 | 22 | NO | NO |
CVE-2010-0468MEDIUM Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url | Feb 2, 2010 | 4.3 | 22 | NO | YES |
CVE-2005-4574MEDIUM Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the | Dec 29, 2005 | 4.3 | 21 | NO | YES |
CVE-2014-2868HIGH PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion v | Apr 15, 2014 | 7.5 | 20 | NO | NO |
CVE-2014-2865HIGH PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demonstrated by using this character | Apr 15, 2014 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paperthin.
Media articles that mention a CVE ID that affects a product developed by Paperthin — matched by CVE ID, not by vendor name.