Known Vulnerabilities for products from Paperthin

Listed below are 19 of the newest known vulnerabilities associated with the vendor "Paperthin".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2014-2874 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharac... Not Provided 2014-04-15 2026-05-06
CVE-2014-2873 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows ... Not Provided 2014-04-15 2026-05-06
CVE-2014-2872 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information fr... Not Provided 2014-04-15 2026-05-06
CVE-2014-2871 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, whi... Not Provided 2014-04-15 2026-05-06
CVE-2014-2870 json The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials... Not Provided 2014-04-15 2026-05-06
CVE-2014-2869 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests t... Not Provided 2014-04-15 2026-05-06
CVE-2014-2868 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion ... Not Provided 2014-04-15 2026-05-06
CVE-2014-2867 json Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to e... Not Provided 2014-04-15 2026-05-06
CVE-2014-2866 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows... Not Provided 2014-04-15 2026-05-06
CVE-2014-2865 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '... Not Provided 2014-04-15 2026-05-06
CVE-2014-2864 json Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers... Not Provided 2014-04-15 2026-05-06
CVE-2014-2863 json Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attac... Not Provided 2014-04-15 2026-05-06
CVE-2014-2862 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows r... Not Provided 2014-04-15 2026-05-06
CVE-2014-2861 json Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to condu... Not Provided 2014-04-15 2026-05-06
CVE-2014-2860 json Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote at... Not Provided 2014-04-15 2026-05-06
CVE-2014-2859 json PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a d... Not Provided 2014-04-15 2026-05-06
CVE-2010-0468 json Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attac... Not Provided 2010-02-02 2026-04-29
CVE-2005-4575 json PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid err... Not Provided 2005-12-29 2025-04-03
CVE-2005-4574 json Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote a... Not Provided 2005-12-29 2025-04-03

Known software with vulnerabilities from Paperthin

Type Vendor Product Version
ApplicationPaperthinCommonspot Content Server-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report