Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Aug 18, 2025

CVE-2023-2533

High
EPSS 36.3%CISA KEV
PaperCut/NG/MF

Description

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

EPSS — Exploit Probability

36.3%

Higher than 97.0% of all CVEs

Required Action

https://www.papercut.com/kb/Main/SecurityBulletinJune2023 ; https://nvd.nist.gov/vuln/detail/CVE-2023-2533

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
36.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jul 28, 2025

Added to KEV

Jul 28, 2025

Remediation Due

Aug 18, 2025

Affected Product

PaperCut

NG/MF

View all PaperCut CVEs