PT-2026-30853 · Papra · Papra

·

CVE-2026-35460

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Papra versions prior to 26.4.0
Description Papra is a minimalistic document management and archiving platform. Prior to version 26.4.0, transactional email templates interpolate user.name directly into HTML without proper escaping or sanitization. An attacker registering with a display name containing HTML tags can inject those tags into the verification and password reset email bodies. Because emails originate from a legitimate domain (e.g., auth@mail.papra.app), this enables convincing phishing attacks that appear to come from official Papra notifications.
Recommendations Update to version 26.4.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35460
GHSA-6F8X-2RC9-VGH4

Affected Products

Papra