Home/Product/9001 copyparty
Product

9001 copyparty

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-32109
< 1.20.12
Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read-and write-permissions to the server
3.7LOW
CVE-2026-32108
< 1.20.12
Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-
6.5MEDIUM
CVE-2026-30974
< 1.20.11
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in
4.6MEDIUM
CVE-2026-27948
< 1.20.9
Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-paramet
5.4MEDIUM
CVE-2025-58753
< 1.19.8
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the
7.5HIGH
CVE-2023-41471
all versions
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted paylo
7.8HIGH
CVE-2025-54796
< 1.18.9
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary
7.5HIGH
CVE-2025-54589
< 1.18.7
Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at /?ru, users can fil
6.3MEDIUM
CVE-2025-54423
< 1.18.5
copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execu
5.4MEDIUM
CVE-2025-27145
< 1.16.15
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerabil
3.6LOW
CVE-2023-38501
< 1.8.7
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-param
6.3MEDIUM
CVE-2023-37474
< 1.8.2
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the .cpr
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin