Pydio
Vendor:
First CVE: Dec 27, 2014 · Active for 11 years
20
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pydio over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2014
11 years ago
Most Recent CVE
Apr 17, 2025
467 days ago
CVE Severity & Scoring
Pydio20 CVEs
45%
35%
20%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (95.0%)
Unknown1 (5.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High1 (5.0%)
Unknown1 (5.0%)
User Interaction
None14 (70.0%)
Unknown1 (5.0%)
Required5 (25.0%)
Privileges Required
Low6 (30.0%)
High4 (20.0%)
None9 (45.0%)
Unknown1 (5.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20718CRITICAL In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs | Jan 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2013-6227HIGH Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute | Dec 27, 2014 | 7.5 | 31 | NO | YES |
CVE-2019-20453HIGH A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authentic | Mar 17, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-20452HIGH A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An au | Mar 17, 2020 | 8.8 | 27 | NO | NO |
CVE-2015-3431CRITICAL Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities." | Sep 19, 2017 | 9.8 | 27 | NO | NO |
CVE-2018-14772HIGH Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code | Oct 16, 2018 | 7.2 | 26 | NO | NO |
CVE-2013-4267CRITICAL Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.pow | Feb 11, 2020 | 9.8 | 25 | NO | NO |
CVE-2019-15033HIGH Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to | Sep 19, 2019 | 7.7 | 25 | NO | NO |
CVE-2019-9642CRITICAL An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourt | Jun 5, 2019 | 9.8 | 24 | NO | NO |
CVE-2019-10048HIGH The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user supplied input in the plugin's confi | May 31, 2019 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Pydio
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.2.2 | 1 | 5.3 | 1.2% | 0 | 0 |
| 6.0.8 | 2 | 6.5 | 1.5% | 0 | 0 |