Printeron is a niche printing-management and central-print-services vendor whose vulnerability profile reflects its role in document-handling infrastructure and administrative web interfaces. The recurring exposure centers on web application security weaknesses—principally cross-site scripting, cross-site request forgery, improper authentication, and improper authorization—alongside information-disclosure risks characteristic of systems managing sensitive print jobs and user credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Printeron over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17213HIGH An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session c | Jul 29, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-17210HIGH An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the | Jul 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-17169HIGH An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SS | Apr 23, 2019 | 7.7 | 24 | NO | NO |
CVE-2018-17168MEDIUM PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can b | Apr 18, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-17211MEDIUM An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted H | Jul 29, 2019 | 5.3 | 21 | NO | NO |
CVE-2018-19936MEDIUM PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion. | Dec 17, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-10327HIGH PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_c | May 17, 2018 | 7.0 | 20 | NO | NO |
CVE-2018-17167MEDIUM PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configur | Mar 21, 2019 | 5.4 | 19 | NO | NO |
CVE-2018-10326MEDIUM PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the pr | May 17, 2018 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Printeron.
Media articles that mention a CVE ID that affects a product developed by Printeron — matched by CVE ID, not by vendor name.