Cells
Pydio · 17 CVEs
Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler
Aug 18, 2026
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are gener…
Jun 8, 2023
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which…
Jun 8, 2023
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying…
Jun 8, 2023
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to en…
Sep 30, 2021
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via…
Sep 30, 2021
Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite persona…
Sep 30, 2021
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio C…
Jun 11, 2020
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shar…
Jun 5, 2020
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user…
Jun 5, 2020
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users wit…
Jun 4, 2020
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cell…
Jun 4, 2020
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key…
Jun 4, 2020
Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicio…
Jun 4, 2020
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and inc…
Jun 19, 2019
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the sa…
Jun 19, 2019
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload file…
Jun 19, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-76032 | Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler | MEDIUM | 0.38% | Aug 18, 2026 |
| CVE-2023-32751 | Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaSc… | MEDIUM | 2.94% | Jun 8, 2023 |
| CVE-2023-32750 | Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "rem… | MEDIUM | 3.85% | Jun 8, 2023 |
| CVE-2023-32749 | Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such… | HIGH | 14.09% | Jun 8, 2023 |
| CVE-2021-41324 | Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files b… | MEDIUM | 2.12% | Sep 30, 2021 |
| CVE-2021-41325 | Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, su… | MEDIUM | 1.15% | Sep 30, 2021 |
| CVE-2021-41323 | Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any… | MEDIUM | 2.08% | Sep 30, 2021 |
| CVE-2020-12850 | The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0… | HIGH | 0.49% | Jun 11, 2020 |
| CVE-2020-12848 | In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backen… | MEDIUM | 1.10% | Jun 5, 2020 |
| CVE-2020-12849 | Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later… | MEDIUM | 0.83% | Jun 5, 2020 |
| CVE-2020-12847 | Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This console pr… | HIGH | 1.68% | Jun 4, 2020 |
| CVE-2020-12851 | Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a… | HIGH | 1.45% | Jun 4, 2020 |
| CVE-2020-12852 | The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update… | MEDIUM | 2.35% | Jun 4, 2020 |
| CVE-2020-12853 | Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal… | MEDIUM | 0.76% | Jun 4, 2020 |
| CVE-2019-12903 | Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as… | MEDIUM | 0.93% | Jun 19, 2019 |
| CVE-2019-12902 | Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore… | MEDIUM | 1.12% | Jun 19, 2019 |
| CVE-2019-12901 | Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an… | HIGH | 1.66% | Jun 19, 2019 |
Showing 1 to 17 of 17 CVEs