CVE-2023-4568: PaperCut NG

Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

Affected products

  • PaperCut PaperCut NG: up to and including 22.0.12

Published 2023-09-13. Last modified 2026-06-17.