CVE-2025-54589

MEDIUM NUCLEI

9001 Copyparty < 1.18.7 - Basic XSS

Title source: rule

Description

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without proper escaping, allowing for reflected Cross-Site Scripting (XSS) and can be exploited against both authenticated and unauthenticated users. This is fixed in version 1.18.7.

Exploits (2)

exploitdb WORKING POC
by Byte Reaper · cwebappsmultiple
https://www.exploit-db.com/exploits/52390
nomisec WORKING POC 2 stars
by byteReaper77 · poc
https://github.com/byteReaper77/CVE-2025-54589

Nuclei Templates (1)

Copyparty <=1.18.6 - Cross-Site Scripting
MEDIUMVERIFIEDby s-cu-bot
Shodan: http.title:"copyparty"
FOFA: title="copyparty"

Scores

CVSS v3 6.3
EPSS 0.0078
EPSS Percentile 73.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
9001/copyparty < 1.18.7
pypi/copyparty 0 - 1.18.7PyPI
Published Jul 31, 2025
Tracked Since Feb 18, 2026