CVE-2026-4794

Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session).
Configurations

Configuration 1 (hide)

cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*

History

03 Apr 2026, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
References () https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/ - () https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/ - Vendor Advisory
CPE cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
First Time Papercut papercut Mf
Papercut
Papercut papercut Ng

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Múltiples vulnerabilidades de cross-site scripting (XSS) en PaperCut NG/MF anteriores a la versión 25.0.10 permiten a usuarios administradores autenticados inyectar scripts web o código HTML arbitrarios a través de diferentes campos de la interfaz de usuario. Esto podría usarse para comprometer las sesiones de otros administradores o realizar acciones no autorizadas a través del contexto autenticado del administrador (por ejemplo, requiere una sesión de inicio de sesión activa).

31 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 01:16

Updated : 2026-04-03 18:15


NVD link : CVE-2026-4794

Mitre link : CVE-2026-4794

CVE.ORG link : CVE-2026-4794


JSON object : View

Products Affected

papercut

  • papercut_ng
  • papercut_mf
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')