pyload-ng vulnerabilities
CVEs whose affected-version data names the pyload-ng package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
29 CVEsRSS
CVE-2026-46561Medium· 5.0pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
CVE-2026-45306Medium· 6.5pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
CVE-2026-45348High· 8.7pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
CVE-2026-44226Medium· 5.3PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
CVE-2026-41133High· 8.8pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVE-2026-40071Medium· 5.4pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
CVE-2026-35463High· 8.8pyLoad: Improper Neutralization of Special Elements used in an OS Command
pyLoad: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-35187High· 7.7pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
CVE-2026-35464High· 7.5pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33…
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
CVE-2026-33509High· 7.5pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
CVE-2025-61773High· 8.1pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
CVE-2025-57751HighDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
CVE-2025-55156HighPyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2025-54140High· 7.5`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
CVE-2025-53890Critical· 9.8pyLoad vulnerable to XSS through insecure CAPTCHA
pyLoad vulnerable to XSS through insecure CAPTCHA
CVE-2025-7346High· 7.5pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
CVE-2024-32880Critical· 9.1pyLoad allows upload to arbitrary folder lead to RCE
pyLoad allows upload to arbitrary folder lead to RCE
CVE-2024-24808Medium· 6.1pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
pyload Log Injection vulnerability
CVE-2023-47890High· 7.6Download to arbitrary folder can lead to RCE
Download to arbitrary folder can lead to RCE
CVE-2023-0488Medium· 5.4Cross-site Scripting in pyload-ng
Cross-site Scripting in pyload-ng
CVE-2023-0509High· 7.4Improper Certificate Validation in pyload-ng
Improper Certificate Validation in pyload-ng
CVE-2023-0434Medium· 5.4Improper Input Validation in pyload-ng
Improper Input Validation in pyload-ng
CVE-2023-0227Medium· 6.5Pyload Insufficient Session Expiration vulnerability
Pyload Insufficient Session Expiration vulnerability
CVE-2023-0055Medium· 5.3Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-0057Medium· 6.1pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames
pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames