Home/Product/pydio cells
Product

pydio cells

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-32751
< 3.0.12
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using
5.4MEDIUM
CVE-2023-32750
< 3.0.12
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in
6.5MEDIUM
CVE-2023-32749
< 3.0.12
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP re
8.8HIGH
CVE-2021-41324
all versions
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate per
6.5MEDIUM
CVE-2021-41325
all versions
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profil
6.5MEDIUM
CVE-2021-41323
all versions
Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or
6.5MEDIUM
CVE-2020-12850
all versions
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterp
7.0HIGH
CVE-2020-12849
all versions
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. Thes
5.4MEDIUM
CVE-2020-12848
all versions
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user acc
5.4MEDIUM
CVE-2020-12853
all versions
Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and
6.1MEDIUM
CVE-2020-12852
all versions
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to va
6.8MEDIUM
CVE-2020-12851
all versions
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders
8.1HIGH
CVE-2020-12847
all versions
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an ad
7.2HIGH
CVE-2019-12903
< 1.5.0
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the d
4.3MEDIUM
CVE-2019-12902
< 1.5.0
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID
6.5MEDIUM
CVE-2019-12901
< 1.5.0
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and D
8.8HIGH
CVE-2017-17950
all versions
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
8.8HIGH
CVE-2017-17949
all versions
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
6.1MEDIUM
CVE-2017-17948
all versions
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.
6.1MEDIUM
threatengine.sh