
CVE-2026-35460 Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate http://user.name directly into HTML w… https://www.cve.org/CVERecord?id=CVE-2026-35460
Post summary
CVE-2026-35460 in Papra permits direct HTML interpolation of user names, potentially leading to XSS or SSRF risks; updating to version 26.4.0 mitigates the flaw.
