CVEs we hold for Pyload
Records whose assigning authority named Pyload as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-48987pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerpyload
CVE-2026-48737pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPspyload
CVE-2026-45348pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literalpyload
CVE-2026-45306pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directorypyload
CVE-2026-44226pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUIpyload
CVE-2026-42313pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxypyload
CVE-2026-41133pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)pyload
CVE-2026-40594pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)pyload
CVE-2026-40071pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actionspyload
CVE-2026-35592pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypasspyload
CVE-2026-35586Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ngpyload
CVE-2026-35464pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask…pyload
CVE-2026-33992pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltrationpyload
CVE-2026-33509pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configurationpyload
CVE-2026-32808pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verificationpyload
CVE-2025-55156PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameterpyload
CVE-2025-54802pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE)pyload
CVE-2025-54140pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Writepyload
CVE-2024-47821pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APIpyload
CVE-2024-24808pyLoad open redirect vulnerability due to improper validation of the is_safe_url functionpyload
CVE-2024-22416Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalationpyload
CVE-2023-0055Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in pyload/pyloadpyload/pyload
47 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.