Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pyload

First CVE: Jan 4, 2023Active for: 4 yearsTotal CVEs: 24
56.7
VTI Score
TOP TARGET

Pyload is a lightweight download manager and media server that, despite a narrow product scope, occupies a moderately prominent position in the vulnerability landscape, likely due to its open-source nature and exposure as a web-facing application. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making disclosed flaws a high-priority concern for deployments. The exposure recurs consistently through access-control and session-management weakness classes—including path traversal, incorrect authorization, insufficient session expiration, and open redirect—that are characteristic of web application input handling and state management. Defenders should prioritize patches for this vendor given the severity tendency and exploit availability; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pyload over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2023
3 years ago
Most Recent CVE
May 11, 2026
74 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0297CRITICAL
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
Jan 14, 20239.893NOYES
CVE-2024-21644HIGH
pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_
Jan 8, 20247.556NOYES
CVE-2024-21645MEDIUM
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject ar
Jan 8, 20245.337NOYES
CVE-2026-33509HIGH
pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the n
Mar 24, 20268.831NONO
CVE-2023-0435CRITICAL
Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.
Jan 22, 20239.831NONO
CVE-2026-41133HIGH
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues
Apr 22, 20268.830NONO
CVE-2026-33511CRITICAL
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature c
Mar 24, 20269.829NONO
CVE-2026-32808HIGH
pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypte
Mar 20, 20268.127NONO
CVE-2026-35464HIGH
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-cri
Apr 7, 20267.526NONO
CVE-2023-47890HIGH
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
Jan 8, 20248.826NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
42%
42%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.2%)
Network23 (95.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (91.7%)
High2 (8.3%)
Unknown0 (0.0%)
User Interaction
None19 (79.2%)
Unknown0 (0.0%)
Required5 (20.8%)
Privileges Required
Low8 (33.3%)
High2 (8.3%)
None14 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.2% of CVEs· 98th percentile
Nuclei
3 CVEs
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pyload.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pyload — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pyload's Products

View all 4 CNAs →

Top CWEs