28,679 Entries 2,229 Sources 5 Verticals Last sync 5 minutes Live
Dashboard/ Self-hosted apps/ Paperless-ngx
Self-hosted apps

Paperless-ngx

paperless-ngx
v3.0.0-beta.rc1 bewährt latest release
05.05.2026

bewährt — keine offenen Regressionen, etabliert · 0 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

15 CVE(s) zuletzt, höchste Schwere: hoch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 0, 'checked_at': '2026-06-08T02:00:17.118261', 'open_regressions': 0}
gh_etagW/"6fdc2ce040bb94ebc471fb873e78a86c2c07002cd91470b95e2838b187ffeca2"
gh_checked_at2026-06-08T03:15:00.158026+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps Low

A vulnerability in Paperless-ngx allows attackers to access documents through the API even when remote user API access is explicitly disabled, potentially exposing sensitive document contents.

CVE-2024-35184
05.06.2026
CVE
Self-hosted apps Medium

In Paperless-ngx, logged-in users can access files they don't have permission for through a bulk download feature, leading to unauthorized file access.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

Paperless-ngx contains two vulnerabilities that allow authenticated users to inject malicious scripts: through storage path settings or by uploading a manipulated SVG logo file. These scripts can then execute in other users' browsers.

Advisory
05.06.2026
CVE
Self-hosted apps Low

A security vulnerability in Paperless-ngx's webhook functionality allows attackers to bypass internal network access restrictions using DNS rebinding attacks, potentially enabling access to internal systems despite security controls.

Advisory
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Paperless-ngx allows authenticated users to create malicious regular expressions in tags or correspondents that cause extreme CPU usage during document processing, leading to complete service failure.

Advisory
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Paperless-ngx allows attackers to store malicious code in metadata like tags or document types that then executes when other users view the affected interface.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

A security flaw in Paperless-ngx allows authenticated users to write files to arbitrary locations on the filesystem, including system directories, due to insufficient path validation in the Storage Path feature.

Advisory
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Paperless-ngx allows authenticated users without proper permissions to upload and process documents, even when they should only have read-only access.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

In Paperless-ngx, users with document editing permissions can change the document's owner even though they shouldn't have this privilege.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in Paperless-ngx allows any authenticated user to read contents of other users' documents and extract user information, despite lacking proper permissions.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Paperless-ngx allows users to access other users' email passwords by exploiting the email account test function with foreign account IDs without proper permission checks.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Paperless-ngx allows authenticated users to create public links for any documents, even those they lack permission to view, potentially exposing confidential content without authorization.

Advisory
05.06.2026
CVE
Self-hosted apps High

A vulnerability in Paperless-ngx allows authenticated users with user-adding permissions to create superuser accounts through a type coercion flaw, enabling them to escalate their privileges beyond intended access levels.

Advisory
05.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Paperless-ngx allows authenticated users to view other users' email account metadata and email rules through the global search function, even when they shouldn't have permission to access this information.

Advisory
05.06.2026
CVE
Self-hosted apps Low

A vulnerability in Paperless-ngx allows users with delete permissions to remove administrator accounts even though they are not administrators themselves, due to faulty permission checking when deleting user accounts.

Advisory
05.06.2026
REL
Self-hosted apps High bewährt

Major beta release introducing AI features, remote OCR, document versioning, and new search backend. Contains multiple breaking changes including removal of encryption support, API v1 compatibility, Python 3.10 support, and database migration restructuring. Significant upgrade requiring careful migr

v3.0.0-beta.rc1
05.05.2026
REL
Self-hosted apps High bewährt

Security patch release fixing authentication endpoint vulnerabilities and mail account enumeration issues. Also includes fixes for custom field query events and API notes endpoint validation. Upgrade recommended for all users due to security fixes.

v2.20.15
27.04.2026
REL
Self-hosted apps Low bewährt

Bug fix release addressing permissions handling for non-owners, duplicate tag ID prevention, workflow tag processing, share link access controls, document ordering consistency, email correspondent matching defaults, and date field validation improvements.

v2.20.14
14.04.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing search suggestion visibility, permission enforcement for document searches and mail rule account attachments, and validation of document link targets.

v2.20.13
21.03.2026
REL
Self-hosted apps High bewährt

Security patch release fixing workflow filename clobbering vulnerability, along with improvements to file handling, authentication scope, API documentation, and dark mode UI elements.

v2.20.12
20.03.2026
REL
Self-hosted apps High bewährt

Security patch release addressing vulnerability GHSA-59xh-5vwx-4c4q along with UI fixes for dark mode dropdown colors, tag display wrapping on small cards, dropdown selection behavior, and database filename handling during workflow actions.

v2.20.11
16.03.2026
REL
Self-hosted apps Medium bewährt

Bug fix release addressing storage path template issues from v2.20.7, including fixes for Jinja template string handling, tag document count ordering, and database filename field path limits. Users with affected storage paths should run the document_renamer command after updating.

v2.20.10
04.03.2026
REL
Self-hosted apps High bewährt

Security patch release addressing vulnerability GHSA-386h-chg4-cfw9, plus fixes for configuration option reset functionality and tag page count display issues.

v2.20.9
28.02.2026
REL
Self-hosted apps High bewährt

Security patch release addressing vulnerability GHSA-7qqc-wrcw-2fj9, recommended for all users to upgrade immediately.

v2.20.8
22.02.2026
REL
Self-hosted apps High bewährt

Security release that restricts filename template rendering context, potentially breaking templates using undocumented document properties. Also fixes user interface styling, Docker classifier command, and improves performance for large installations.

v2.20.7
16.02.2026
REL
Self-hosted apps High bewährt

Security patch release addressing two security vulnerabilities with fixes for nested tag extraction, note deletion prevention, performance improvements for tree nodes, date calculation corrections, rootless management script issues, and field override problems.

v2.20.6
31.01.2026
REL
Self-hosted apps Low bewährt

Minor bug fix release addressing UI display issues with long tag names and workflow action ordering. Improves horizontal scrolling for tags and ensures proper sequencing of workflow actions.

v2.20.5
21.01.2026
REL
Self-hosted apps High bewährt

Security patch release fixing a reported vulnerability along with several bug fixes including metadata override propagation, storage path ordering, PostgreSQL integer validation, index error handling, and recurring workflow timing issues.

v2.20.4
13.01.2026
REL
Self-hosted apps High bewährt

Security patch release that addresses a reported security vulnerability, recommended for all users to upgrade immediately.

v2.20.3
18.12.2025
REL
Self-hosted apps High bewährt

Security patch release addressing two security vulnerabilities with improved SVG validation, tag serializer permission fixes, and minor UI enhancements for inactive user display. Includes dependency updates and performance optimizations for bulk operations.

v2.20.2
12.12.2025
REL
Self-hosted apps Low bewährt

Patch release fixing search functionality issues, custom field update handling, MariaDB SSL connection problems, and allauth compatibility. Also includes minor dependency updates for Docker and Angular components.

v2.20.1
01.12.2025
REL
Self-hosted apps Low bewährt

Paperless-ngx 2.20.0 upgrades Docker base image to Debian Trixie, improves log viewer functionality, adds relative date support, enhances performance with async file operations and symlinked static files, fixes custom field dropdown issues, and updates multiple dependencies including psycopg, Angula

v2.20.0
22.11.2025
REL
Self-hosted apps Low bewährt

Bug fix release addressing email attachment handling, workflow URL construction, Outlook token refresh, search whitespace trimming, storage path preview logic, version checking cache, and user password validation improvements.

v2.19.6
15.11.2025
REL
Self-hosted apps Low bewährt

Bug fix release addressing custom field query propagation and change detection issues, plus dependency update for astral-sh/uv Docker image from version 0.9.4 to 0.9.7.

v2.19.5
06.11.2025
REL
Self-hosted apps Low bewährt

Bug fix release addressing workflow email attachments, UI translation issues, field parameter handling, mail error display improvements, print functionality in Firefox, tag filtering duplicates, and performance enhancements with virtual scrolling and log handling optimizations.

v2.19.4
04.11.2025
REL
Self-hosted apps Low bewährt

Paperless-ngx 2.19.3 patch release addressing multiple UI and functionality issues including email endpoint permissions, dropdown sorting, tag filtering, email attachment support, missing component imports, and migration warnings. Also updates Django dependency and improves workflow handling.

v2.19.3
29.10.2025
REL
Self-hosted apps Low bewährt

Minor patch release fixing UI issues including tag loading display, bulk email permission requirements, and undefined ID handling in object retrieval functions.

v2.19.2
23.10.2025
REL
Self-hosted apps Low bewährt

Bug fix release addressing workflow title migration issues, tag hierarchy display problems, document count retrieval for tag children, dropdown sorting logic, and permission-based user/group visibility restrictions.

v2.19.1
22.10.2025
REL
Self-hosted apps Low bewährt

Paperless-ngx 2.19.0 adds advanced workflow filters, nested tags, email enhancements for multiple documents, performance improvements for permission caching, and various UI improvements including print buttons and custom field support. Includes multiple bug fixes for UI components, document processi

v2.19.0
21.10.2025
REL
Self-hosted apps Low bewährt

Paperless-ngx maintenance release with websocket status reporting, sidebar view count fixes, custom field performance improvements, virtual scrolling revert, and dependency updates including Angular, Bootstrap, and development tools.

v2.18.4
07.09.2025
REL
Self-hosted apps Low bewährt

Bug fix release addressing UI issues including date parsing language settings, sidebar display problems, view title wrapping, and pagination schema validation. Also includes performance improvements for custom field selects and dependency updates.

v2.18.3
02.09.2025
REL
Self-hosted apps Low bewährt

Paperless-ngx patch release addressing UI bugs including data loss prevention when switching documents, system status display improvements, date filter visibility enhancements, and saved view count display fixes, plus development dependency updates.

v2.18.2
22.08.2025
REL
Self-hosted apps Low bewährt

Minor patch release addressing UI consistency issues including button styling fixes, mobile layout improvements for PDF editor, and a bug fix for app logo validation when no file is present.

v2.18.1
17.08.2025
REL
Self-hosted apps Medium Breaking

Paperless-ngx 2.18.0 introduces PostgreSQL 14+ requirement (breaking change), adds PDF editor functionality, performance optimizations including database connection pooling, Vietnamese translation support, and fixes XSS security vulnerability along with various bug fixes and UI enhancements.

v2.18.0
16.08.2025
REL
Self-hosted apps Low bewährt

Bug fix release that corrects the PAPERLESS_EMPTY_TRASH_DIR configuration to properly handle Path objects instead of strings, resolving potential issues with trash directory management.

v2.17.1
19.06.2025