Cross-Site Scripting Vulnerabilities in PaperCut NG/MF by PaperCut
CVE-2026-4794

2.1LOW

Key Information:

Vendor

Papercut

Vendor
CVE Published:
31 March 2026

What is CVE-2026-4794?

Multiple cross-site scripting vulnerabilities in PaperCut NG/MF allow authenticated administrators to inject arbitrary web scripts or HTML code through various UI fields. This could lead to the compromise of other administrators' sessions or enable unauthorized actions within the context of an authenticated administrator's session, particularly when an active login is required.

Affected Version(s)

PaperCut NG/MF Windows 0 < 25.0.10

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.