CVE-2018-9327: Etherpad
High severity, CVSS 8.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
Affected products
- Etherpad Etherpad: from 1.5.0, up to and including 1.5.7; from 1.6.0, before 1.6.4 (fixed in 1.6.4)
Published 2018-04-07. Last modified 2026-06-17.