9001
9001 Copyparty: vulnerabilidades y CVE
9001 Copyparty tiene 14 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93353 | Baja (2.3) | 0.27% | — | 24 sept 2026 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting… |
| CVE-2026-70657 | Media (4.3) | 0.33% | — | 18 ago 2026 | Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read… |
| CVE-2026-32109 | Media (4.4) | 0.19% | — | 11 mar 2026 | Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to the server, they can upload a malicious file with the filename .prologue.html and then craft a… |
| CVE-2026-32108 | Baja (2.3) | 0.34% | — | 11 mar 2026 | Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the shares feature is used for the specific… |
| CVE-2026-30974 | Media (5.4) | 0.34% | — | 10 mar 2026 | Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could… |
| CVE-2026-27948 | Media (6.1) | 0.27% | — | 26 feb 2026 | Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue. |
| CVE-2025-58753 | Media (5.3) | 0.38% | — | 9 sept 2025 | Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for just one file inside a folder, it was… |
| CVE-2023-41471 | Alta (7.8) | 0.26% | — | 29 ago 2025 | Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is… |
| CVE-2025-54796 | Alta (7.5) | 0.43% | — | 2 ago 2025 | Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a… |
| CVE-2025-54589 | Media (6.1) | 2.4% | — | 31 jul 2025 | Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to… |
| CVE-2025-54423 | Media (6.1) | 0.41% | — | 28 jul 2025 | copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of… |
| CVE-2025-27145 | Media (6.1) | 0.47% | — | 25 feb 2025 | copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then… |
| CVE-2023-38501 | Media (6.1) | 9.2% | — | 25 jul 2023 | copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move… |
| CVE-2023-37474 | Alta (7.5) | 45% | — | 14 jul 2023 | Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.