Vulnerability library
Security checkAugust 13, 2026

ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmep_etherpad-lite

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Severity: Medium CVSS v3.1 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS suggested base score: ~6.1 — Medium *(Re-validate in the first.gov calculator before filing.

Recommendation

Update the ep_etherpad-lite package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 2.1.0, <= 3.0.0
  • Patched version(s): 3.1.0

References

Could your website be exposed too?

SmartScanner can check your website for ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 13, 2026