Products: 2
    Vulnerabilities: 37
    Known Exploited: 0
    4
    Critical Level Threats
    12
    High Level Threats
    21
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-76032

    Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler

    Last Modified: Aug 18, 2026
    Published: Aug 18, 2026

    CVE-2024-40124

    Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.

    Last Modified: Jun 25, 2025
    Published: Apr 17, 2025

    CVE-2023-32750

    Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

    Last Modified: Jan 06, 2025
    Published: Jun 08, 2023

    CVE-2023-32749

    Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.

    Last Modified: Jan 06, 2025
    Published: Jun 08, 2023

    CVE-2023-32751

    Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web application. Therefore, it is possible to generate valid signatures for arbitrary download URLs. By uploading an HTML file and modifying the download URL to serve the file inline instead of as an attachment, any included JavaScript code is executed when the URL is opened in a browser, leading to a cross-site scripting vulnerability.

    Last Modified: Jan 06, 2025
    Published: Jun 08, 2023
    Items Per Page