Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Seafile

First CVE: Mar 19, 2018Active for: 8 yearsTotal CVEs: 12
18.7
VTI Score
Low

Seafile is a file-synchronization and collaborative-storage platform whose vulnerability profile concentrates across its server and client applications, including the core Seafile server, Seadroid mobile client, and desktop sync utilities. The recurring vulnerability patterns center on web-application and authentication-layer weaknesses: cross-site scripting, authorization-bypass conditions rooted in user-controlled access keys, open-redirect flaws, inadequate encryption strength, and search-path manipulation, reflecting the challenges of securing file-sharing workflows and access-control enforcement across distributed clients. Current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Seafile over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 19, 2018
8 years ago
Most Recent CVE
Mar 25, 2026
121 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-30587HIGH
Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc)
Mar 25, 20268.725NONO
CVE-2013-7469HIGH
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext a
Feb 21, 20197.525NONO
CVE-2014-5443HIGH
Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.
Mar 19, 20187.825NONO
CVE-2019-8919HIGH
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt pr
Feb 18, 20197.524NONO
CVE-2025-41079MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by sto
Dec 4, 20256.122NONO
CVE-2025-65516MEDIUM
A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an a
Dec 4, 20256.121NONO
CVE-2021-43820MEDIUM
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cach
Dec 14, 20215.921NONO
CVE-2020-16143HIGH
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
Jul 29, 20207.820NONO
CVE-2025-41080MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by sto
Dec 4, 20256.119NONO
CVE-2021-30146MEDIUM
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
Apr 6, 20215.418NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
58%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (16.7%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low4 (33.3%)
High0 (0.0%)
None8 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Seafile.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Seafile — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Seafile's Products

View all 3 CNAs →

Top CWEs