Papra's vulnerability profile centers on its core web application product and is characterized by recurrent input-handling and session-management weaknesses, notably cross-site scripting variants and server-side request forgery. These web-application-layer flaws reflect typical exposure for a single-product vendor in the web application domain, and current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Papra over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35460MEDIUM Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name directly into HTML without escapin | Apr 7, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-35462MEDIUM Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authenticat | Apr 7, 2026 | 4.3 | 17 | NO | NO |
CVE-2026-35461MEDIUM Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows authenticated users to register arbitrary URLs as webhook endpo | Apr 7, 2026 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Papra.
Media articles that mention a CVE ID that affects a product developed by Papra — matched by CVE ID, not by vendor name.