Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Paperthin

First CVE: Dec 29, 2005Active for: 21 yearsTotal CVEs: 19
43.4
VTI Score
High

Paperthin's vulnerability footprint centers on the CommonSpot Content Server, a web-based content-management platform whose exposure recurs through application-layer input-handling and information-disclosure weaknesses including cross-site scripting, code injection, path traversal, and sensitive data exposure. While the vendor's product scope is narrow, this content server sits as a trusted component in publishing and web-management workflows, making its disclosures relevant to organizations running that platform. Public exploit code has been associated with vulnerabilities in this product class, underscoring the importance of timely patching; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Paperthin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2005
20 years ago
Most Recent CVE
Apr 15, 2014
4,484 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-2874HIGH
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context.
Apr 15, 201410.031NONO
CVE-2014-2867HIGH
Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page, a
Apr 15, 201410.026NONO
CVE-2014-2864HIGH
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter
Apr 15, 201410.026NONO
CVE-2014-2863HIGH
Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname
Apr 15, 201410.026NONO
CVE-2014-2866HIGH
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by
Apr 15, 201410.025NONO
CVE-2014-2859HIGH
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.
Apr 15, 20147.522NONO
CVE-2010-0468MEDIUM
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url
Feb 2, 20104.322NOYES
CVE-2005-4574MEDIUM
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the
Dec 29, 20054.321NOYES
CVE-2014-2868HIGH
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion v
Apr 15, 20147.520NONO
CVE-2014-2865HIGH
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demonstrated by using this character
Apr 15, 20147.520NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
58%
42%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown19 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown19 (100.0%)
User Interaction
None0 (0.0%)
Unknown19 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown19 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Paperthin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Paperthin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Paperthin's Products

View all 1 CNAs →

Top CWEs