Skip to content

Known CVE

Etherpad 2.1.0 <= 3.0.0 - Cross-Site Scripting

Etherpad versions 2.1.0 through 3.0.0 reflect the x-proxy-path request header into admin HTML, JavaScript, and CSS responses without sanitization. An attacker can abuse this behavior to inject crafted content into generated resource URLs, enabling cross-site scripting and cache poisoning scenarios.

CVE-2026-55087

Medium2026CVSS 6.1CWE-79CWE-444CWE-601

cve2026 · etherpad · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website