Known CVE
Etherpad 2.1.0 <= 3.0.0 - Cross-Site Scripting
Etherpad versions 2.1.0 through 3.0.0 reflect the x-proxy-path request header into admin HTML, JavaScript, and CSS responses without sanitization. An attacker can abuse this behavior to inject crafted content into generated resource URLs, enabling cross-site scripting and cache poisoning scenarios.
CVE-2026-55087
Medium2026CVSS 6.1CWE-79CWE-444CWE-601
cve2026 · etherpad · xss
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website