Pydio

Vendor:

First CVE: Dec 27, 2014 · Active for 11 years

20
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pydio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2014
11 years ago
Most Recent CVE
Apr 17, 2025
467 days ago

CVE Severity & Scoring

Pydio20 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (95.0%)
Unknown1 (5.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High1 (5.0%)
Unknown1 (5.0%)
User Interaction
None14 (70.0%)
Unknown1 (5.0%)
Required5 (25.0%)
Privileges Required
Low6 (30.0%)
High4 (20.0%)
None9 (45.0%)
Unknown1 (5.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs
Jan 15, 20199.831NONO
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute
Dec 27, 20147.531NOYES
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authentic
Mar 17, 20208.827NONO
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An au
Mar 17, 20208.827NONO
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
Sep 19, 20179.827NONO
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code
Oct 16, 20187.226NONO
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.pow
Feb 11, 20209.825NONO
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to
Sep 19, 20197.725NONO
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourt
Jun 5, 20199.824NONO
The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user supplied input in the plugin's confi
May 31, 20197.224NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.0% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Pydio

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.2.215.31.2%00
6.0.826.51.5%00