Cells

Pydio · 17 CVEs

CVE-2026-76032
MEDIUM

Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler

Aug 18, 2026

CVE-2023-32751
MEDIUM

Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are gener…

Jun 8, 2023

CVE-2023-32750
MEDIUM

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which…

Jun 8, 2023

CVE-2023-32749
HIGH

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying…

Jun 8, 2023

CVE-2021-41324
MEDIUM

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to en…

Sep 30, 2021

CVE-2021-41325
MEDIUM

Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via…

Sep 30, 2021

CVE-2021-41323
MEDIUM

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite persona…

Sep 30, 2021

CVE-2020-12850
HIGH

The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio C…

Jun 11, 2020

CVE-2020-12848
MEDIUM

In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shar…

Jun 5, 2020

CVE-2020-12849
MEDIUM

Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user…

Jun 5, 2020

CVE-2020-12847
HIGH

Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users wit…

Jun 4, 2020

CVE-2020-12851
HIGH

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cell…

Jun 4, 2020

CVE-2020-12852
MEDIUM

The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key…

Jun 4, 2020

CVE-2020-12853
MEDIUM

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicio…

Jun 4, 2020

CVE-2019-12903
MEDIUM

Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and inc…

Jun 19, 2019

CVE-2019-12902
MEDIUM

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the sa…

Jun 19, 2019

CVE-2019-12901
HIGH

Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload file…

Jun 19, 2019

Showing 1 to 17 of 17 CVEs