Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-62cr-6wp5-q43h | Copyparty vulnerable to reflected XSS via setck parameter |
Sat, 28 Feb 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:9001:copyparty:*:*:*:*:*:*:*:* |
Fri, 27 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
9001
9001 copyparty |
|
| Vendors & Products |
9001
9001 copyparty |
Thu, 26 Feb 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue. | |
| Title | Copyparty vulnerable to eflected cross-site scripting via setck parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T15:07:56.702Z
Reserved: 2026-02-25T03:11:36.690Z
Link: CVE-2026-27948
Updated: 2026-02-26T15:06:30.004Z
Status : Analyzed
Published: 2026-02-26T02:16:22.733
Modified: 2026-02-28T00:56:59.110
Link: CVE-2026-27948
No data.
OpenCVE Enrichment
Updated: 2026-04-18T17:45:06Z
Github GHSA