vciy

CVEs we hold for Pyload

Records whose assigning authority named Pyload as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-48987pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerpyload
CVE-2026-48737pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPspyload
CVE-2026-46561pyLoad: SSRF via HTTP Redirect Bypass in parse_urls APIpyload
CVE-2026-45348pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literalpyload
CVE-2026-45306pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directorypyload
CVE-2026-44226pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUIpyload
CVE-2026-42315pyLoad: Path Traversal via Package Folder Name in set_package_datapyload
CVE-2026-42314pyLoad: Path Traversal via Package Folder Namepyload
CVE-2026-42313pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxypyload
CVE-2026-42312pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verificationpyload
CVE-2026-41133pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)pyload
CVE-2026-40594pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)pyload
CVE-2026-40071pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actionspyload
CVE-2026-35592pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypasspyload
CVE-2026-35586Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ngpyload
CVE-2026-35464pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask…pyload
CVE-2026-35463pyLoad has Improper Neutralization of Special Elements used in an OS Commandpyload
CVE-2026-35459pyLoad has SSRF fix bypass via HTTP redirectpyload
CVE-2026-35187pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameterpyload
CVE-2026-33992pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltrationpyload
CVE-2026-33511pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoadpyload
CVE-2026-33509pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configurationpyload
CVE-2026-33314pyload-ng: Improper Authentication and Origin Validation Errorpyload
CVE-2026-32808pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verificationpyload
CVE-2026-29778pyLoad: Arbitrary File Write via Path Traversal in edit_package()pyload
CVE-2025-7346no title heldPyload
CVE-2025-61773pyLoad CNL and captcha handlers allow code Injection via unsanitized parameterspyload
CVE-2025-57751Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljspyload
CVE-2025-55156PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameterpyload
CVE-2025-54802pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE)pyload
CVE-2025-54140pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Writepyload
CVE-2025-53890pyLoad vulnerable to remote code execution through js2py onCaptchaResultpyload
CVE-2024-47821pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APIpyload
CVE-2024-32880pyLoad allows upload to arbitrary folder lead to RCEpyload
CVE-2024-24808pyLoad open redirect vulnerability due to improper validation of the is_safe_url functionpyload
CVE-2024-22416Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalationpyload
CVE-2024-21645pyLoad Log Injectionpyload
CVE-2024-21644pyLoad unauthenticated flask configuration leakagepyload
CVE-2024-1240Open Redirection in pyload/pyloadpyload/pyload
CVE-2023-0509Improper Certificate Validation in pyload/pyloadpyload/pyload
CVE-2023-0488Cross-site Scripting (XSS) - Stored in pyload/pyloadpyload/pyload
CVE-2023-0435Excessive Attack Surface in pyload/pyloadpyload/pyload
CVE-2023-0434Improper Input Validation in pyload/pyloadpyload/pyload
CVE-2023-0297Code Injection in pyload/pyloadpyload/pyload
CVE-2023-0227Insufficient Session Expiration in pyload/pyloadpyload/pyload
CVE-2023-0057Improper Restriction of Rendered UI Layers or Frames in pyload/pyloadpyload/pyload
CVE-2023-0055Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in pyload/pyloadpyload/pyload

47 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.