V
Vexday
by TrueHacking
›
PT
ES
EN
Intelligence
▾
Intelligence
Exploit Timeline
risk queue
Threats
ransomware · malware
Overview
observatory
Triage Room
Explore
▾
Explore
CVEs
Technologies
Vendors
Weakness types
Briefing
Live
Home
/
Technologies
/
papra-hq
Vulnerabilities in
papra-hq
3 results
CVE-2026-35462
MEDIUM
Papra Does Not Reject Expired API Keys
EPSS
0.2%
CVE-2026-35461
MEDIUM
Papra has a Blind Server-Side Request Forgery (SSRF) via Webhook URL
EPSS
0.2%
CVE-2026-35460
MEDIUM
Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name
EPSS
0.2%