S4E just found an informational finding from web sayfası erişilebilirlik kontrolü
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Aug 15, 2025

Copyparty <=1.18.6 - Cross-Site Scripting

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
1
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.3
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without proper escaping, allowing for reflected Cross-Site Scripting (XSS) and can be exploited against both authenticated and unauthenticated users. This is fixed in version 1.18.7.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
copypartyby 9001
< 1.18.7
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Copyparty <=1.18.6 - Cross-Site Scripting CVE-2025-54589 Scanner | S4E