VulnSea

ep_etherpad-lite vulnerabilities

CVEs whose affected-version data names the ep_etherpad-lite package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-55090High
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute esc…

Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.41%via NVD
CVE-2026-55086Medium· 4.2
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared wo…

Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.18%via NVD
CVE-2026-55088Medium· 6.8
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTra…

Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.36%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.52%via NVD
GHSA-92hr-gmr6-h8cpMedium
1mo ago

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
ep_etherpad-lite vulnerabilities (CVEs) · VulnSea