Repetier Server is a web-based control and management platform for 3D printers, presenting a narrow but Internet-accessible attack surface concentrated in a single widely deployed product. The observed vulnerabilities reflect the application's remote-access and device-control role; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Repetier Server over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31059HIGH Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php. | Apr 24, 2023 | 7.5 | 37 | NO | YES |
CVE-2019-14450CRITICAL A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an uninte | Oct 28, 2019 | 9.8 | 34 | NO | NO |
CVE-2019-14451CRITICAL RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined | Oct 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-31060CRITICAL Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise. | Apr 24, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-31061HIGH Repetier Server through 1.4.10 does not have CSRF protection. | Apr 24, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Repetier Server.
Media articles that mention a CVE ID that affects a product developed by Repetier Server — matched by CVE ID, not by vendor name.