Pydio develops a modestly represented but prominently deployed file-collaboration and content-management platform, with its core products Pydio and Cells sitting at the intersection of web-facing storage and user-authentication infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency to reach critical severity and frequently acquire public exploit code, reflecting the sensitive data-access and system-integration role these products occupy. The exposure recurs across input-handling and data-processing boundaries through weakness classes including cross-site scripting, path traversal, OS command injection, untrusted deserialization, and server-side request forgery—a pattern characteristic of file-serving platforms that parse user input, construct system commands, and interact with backend services. Defenders should treat Pydio advisories as high-priority for internet-reachable instances and verify file-access boundaries closely; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pydio over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32749HIGH Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it | Jun 8, 2023 | 8.8 | 44 | NO | YES |
CVE-2023-32750MEDIUM Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be | Jun 8, 2023 | 6.5 | 31 | NO | YES |
CVE-2018-20718CRITICAL In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs | Jan 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2013-6227HIGH Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute | Dec 27, 2014 | 7.5 | 31 | NO | YES |
CVE-2023-32751MEDIUM Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets | Jun 8, 2023 | 5.4 | 27 | NO | YES |
CVE-2019-20453HIGH A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authentic | Mar 17, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-20452HIGH A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An au | Mar 17, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-12901HIGH Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged director | Jun 20, 2019 | 8.8 | 27 | NO | NO |
CVE-2015-3431CRITICAL Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities." | Sep 19, 2017 | 9.8 | 27 | NO | NO |
CVE-2018-14772HIGH Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code | Oct 16, 2018 | 7.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pydio.
Media articles that mention a CVE ID that affects a product developed by Pydio — matched by CVE ID, not by vendor name.