Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pydio

First CVE: Dec 27, 2014Active for: 12 yearsTotal CVEs: 36
36.5
VTI Score
Medium

Pydio develops a modestly represented but prominently deployed file-collaboration and content-management platform, with its core products Pydio and Cells sitting at the intersection of web-facing storage and user-authentication infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency to reach critical severity and frequently acquire public exploit code, reflecting the sensitive data-access and system-integration role these products occupy. The exposure recurs across input-handling and data-processing boundaries through weakness classes including cross-site scripting, path traversal, OS command injection, untrusted deserialization, and server-side request forgery—a pattern characteristic of file-serving platforms that parse user input, construct system commands, and interact with backend services. Defenders should treat Pydio advisories as high-priority for internet-reachable instances and verify file-access boundaries closely; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pydio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2014
11 years ago
Most Recent CVE
Apr 17, 2025
463 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-32749HIGH
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it
Jun 8, 20238.844NOYES
CVE-2023-32750MEDIUM
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be
Jun 8, 20236.531NOYES
CVE-2018-20718CRITICAL
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs
Jan 15, 20199.831NONO
CVE-2013-6227HIGH
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute
Dec 27, 20147.531NOYES
CVE-2023-32751MEDIUM
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets
Jun 8, 20235.427NOYES
CVE-2019-20453HIGH
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authentic
Mar 17, 20208.827NONO
CVE-2019-20452HIGH
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An au
Mar 17, 20208.827NONO
CVE-2019-12901HIGH
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged director
Jun 20, 20198.827NONO
CVE-2015-3431CRITICAL
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
Sep 19, 20179.827NONO
CVE-2018-14772HIGH
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code
Oct 16, 20187.226NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
56%
33%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.8%)
Network34 (94.4%)
Unknown1 (2.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (91.7%)
High2 (5.6%)
Unknown1 (2.8%)
User Interaction
None25 (69.4%)
Unknown1 (2.8%)
Required10 (27.8%)
Privileges Required
Low18 (50.0%)
High6 (16.7%)
None11 (30.6%)
Unknown1 (2.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pydio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pydio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pydio's Products

View all 2 CNAs →

Top CWEs