CVE-2018-9325: Etherpad

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.

Affected products

  • Etherpad Etherpad: from 1.5.0, up to and including 1.5.7; from 1.6.0, before 1.6.4 (fixed in 1.6.4)

Published 2018-04-07. Last modified 2026-06-17.