Pyload is a lightweight download manager and media server that, despite a narrow product scope, occupies a moderately prominent position in the vulnerability landscape, likely due to its open-source nature and exposure as a web-facing application. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making disclosed flaws a high-priority concern for deployments. The exposure recurs consistently through access-control and session-management weakness classes—including path traversal, incorrect authorization, insufficient session expiration, and open redirect—that are characteristic of web application input handling and state management. Defenders should prioritize patches for this vendor given the severity tendency and exploit availability; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyload over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0297CRITICAL Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | Jan 14, 2023 | 9.8 | 93 | NO | YES |
CVE-2024-21644HIGH pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_ | Jan 8, 2024 | 7.5 | 56 | NO | YES |
CVE-2024-21645MEDIUM pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject ar | Jan 8, 2024 | 5.3 | 37 | NO | YES |
CVE-2026-33509HIGH pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the n | Mar 24, 2026 | 8.8 | 31 | NO | NO |
CVE-2023-0435CRITICAL Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. | Jan 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-41133HIGH pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues | Apr 22, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-33511CRITICAL pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature c | Mar 24, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-32808HIGH pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypte | Mar 20, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-35464HIGH pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-cri | Apr 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-47890HIGH pyLoad 0.5.0 is vulnerable to Unrestricted File Upload. | Jan 8, 2024 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyload.
Media articles that mention a CVE ID that affects a product developed by Pyload — matched by CVE ID, not by vendor name.