Ajaxplorer is a self-hosted file-sharing and document-management platform with a narrow product footprint but notable prominence in the web-application vulnerability landscape. Its disclosures cluster around access-control and input-handling weaknesses—path traversal, cross-site request forgery, authentication flaws, and cross-site scripting—that are characteristic of web-facing file-management services, and public exploit code has frequently been available for these classes of flaws. Defenders deploying this product should prioritize patching and restrict network exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ajaxplorer over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-10013CRITICAL An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script wit | Aug 8, 2025 | 9.3 | 44 | NO | YES |
CVE-2013-6227HIGH Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute | Dec 27, 2014 | 7.5 | 31 | NO | YES |
CVE-2013-5688MEDIUM Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash e | Nov 5, 2013 | 5.5 | 30 | NO | YES |
CVE-2013-6226HIGH Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to read or delet | Nov 14, 2013 | 8.5 | 26 | NO | NO |
CVE-2012-1840HIGH AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge o | Mar 22, 2012 | 7.5 | 25 | NO | NO |
CVE-2012-1839HIGH Multiple directory traversal vulnerabilities in the Get Template feature in plugins/gui.ajax/class.AJXP_ClientDriver.php in AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 all | Mar 22, 2012 | 7.5 | 24 | NO | NO |
CVE-2022-40358MEDIUM An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload. | Sep 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2008-6639MEDIUM Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that | Apr 7, 2009 | 6.8 | 18 | NO | NO |
CVE-2015-5650MEDIUM Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors. | Oct 6, 2015 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ajaxplorer.
Media articles that mention a CVE ID that affects a product developed by Ajaxplorer — matched by CVE ID, not by vendor name.