CVE-2026-4794 PUBLISHED

Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF

Assigner: PaperCut
Reserved: 25.03.2026 Published: 31.03.2026 Updated: 31.03.2026

Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session).

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.1

Product Status

Vendor PaperCut
Product PaperCut NG/MF
Versions Default: unaffected
  • affected from 0 to 25.0.10 (excl.)

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS
  • CAPEC-592 Stored XSS
  • CAPEC-63 Cross-Site Scripting (XSS)