Seafile is a file-synchronization and collaborative-storage platform whose vulnerability profile concentrates across its server and client applications, including the core Seafile server, Seadroid mobile client, and desktop sync utilities. The recurring vulnerability patterns center on web-application and authentication-layer weaknesses: cross-site scripting, authorization-bypass conditions rooted in user-controlled access keys, open-redirect flaws, inadequate encryption strength, and search-path manipulation, reflecting the challenges of securing file-sharing workflows and access-control enforcement across distributed clients. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seafile over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30587HIGH Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) | Mar 25, 2026 | 8.7 | 25 | NO | NO |
CVE-2013-7469HIGH Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext a | Feb 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2014-5443HIGH Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts. | Mar 19, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-8919HIGH The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt pr | Feb 18, 2019 | 7.5 | 24 | NO | NO |
CVE-2025-41079MEDIUM A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by sto | Dec 4, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-65516MEDIUM A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an a | Dec 4, 2025 | 6.1 | 21 | NO | NO |
CVE-2021-43820MEDIUM Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cach | Dec 14, 2021 | 5.9 | 21 | NO | NO |
CVE-2020-16143HIGH The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory. | Jul 29, 2020 | 7.8 | 20 | NO | NO |
CVE-2025-41080MEDIUM A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by sto | Dec 4, 2025 | 6.1 | 19 | NO | NO |
CVE-2021-30146MEDIUM Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality." | Apr 6, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seafile.
Media articles that mention a CVE ID that affects a product developed by Seafile — matched by CVE ID, not by vendor name.