Pyload
Pyload: vulnerabilidades y CVE
Pyload tiene 33 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses14
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48987 | Media (6.5) | 0.44% | — | 15 sept 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid… |
| CVE-2026-48737 | Media (4.9) | 0.29% | — | 15 sept 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining… |
| CVE-2026-46561 | Media (5) | 0.29% | — | 28 may 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated… |
| CVE-2026-45348 | Alta (8.7) | 0.35% | — | 28 may 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL… |
| CVE-2026-45306 | Media (6.5) | 0.41% | — | 28 may 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session… |
| CVE-2026-44226 | Media (5.3) | 0.41% | — | 11 may 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is… |
| CVE-2026-41133 | Alta (8.8) | 0.47% | — | 22 abr 2026 | pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these… |
| CVE-2026-40071 | Media (5.4) | 0.32% | — | 9 abr 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core… |
| CVE-2026-35464 | Alta (7.5) | 0.61% | — | 7 abr 2026 | pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The… |
| CVE-2026-33992 | Crítica (9.3) | 0.45% | — | 27 mar 2026 | pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF)… |
| CVE-2026-33511 | Alta (8.8) | 0.62% | — | 24 mar 2026 | pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker… |
| CVE-2026-33509 | Alta (8.8) | 0.58% | — | 24 mar 2026 | pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify… |
| CVE-2026-32808 | Alta (8.1) | 0.46% | — | 20 mar 2026 | pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with… |
| CVE-2025-61773 | Alta (8.1) | 0.41% | — | 9 oct 2025 | pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the Captcha script endpoint and the… |
| CVE-2025-57751 | Alta (7.7) | 0.33% | — | 21 ago 2025 | pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is… |
| CVE-2025-55156 | Alta (7.8) | 0.33% | — | 11 ago 2025 | pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete… |
| CVE-2025-54140 | Alta (7.5) | 0.65% | — | 22 jul 2025 | pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the… |
| CVE-2025-53890 | Crítica (9.8) | 1.2% | — | 15 jul 2025 | pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in… |
| CVE-2024-1240 | Media (6.1) | 0.33% | — | 15 nov 2024 | An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to… |
| CVE-2024-47821 | Baja (2.3) | 0.68% | — | 25 oct 2024 | pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a… |
| CVE-2024-32880 | Alta (7.2) | 1.4% | — | 26 abr 2024 | pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix… |
| CVE-2024-24808 | Media (6.1) | 0.55% | — | 6 feb 2024 | pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the… |
| CVE-2023-47890 | Alta (8.8) | 1.1% | — | 8 ene 2024 | pyLoad 0.5.0 is vulnerable to Unrestricted File Upload. |
| CVE-2024-21645 | Media (5.3) | 25% | — | 8 ene 2024 | pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject arbitrary messages into the logs gathered… |
| CVE-2024-21644 | Alta (7.5) | 42% | — | 8 ene 2024 | pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been… |
| CVE-2023-0509 | Alta (7.4) | 0.53% | — | 26 ene 2023 | Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44. |
| CVE-2023-0488 | Media (5.4) | 0.83% | — | 26 ene 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42. |
| CVE-2023-0435 | Crítica (9.8) | 0.73% | — | 22 ene 2023 | Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41. |
| CVE-2023-0434 | Alta (7.5) | 0.82% | — | 22 ene 2023 | Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40. |
| CVE-2023-0297 | Crítica (9.8) | 96% | — | 14 ene 2023 | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.