All 38 CVE vulnerabilities found in pyload, with AI-generated Chinese analysis, references, and POCs.
This page aggregates known security vulnerabilities for the Python-based download management tool pyload, focusing specifically on weakness types affecting the application and its dependencies. The collection covers reported security flaws disclosed for pyload, spanning the available historical record from its initial releases through recent updates, including issues in dependency libraries and core components. Here, users can track the vendor's security advisories, understand the specific classes of weaknesses such as input validation errors or improper resource management, and look up the complete vulnerability history for this product to assess risk and prioritize remediation efforts.
Vendor: pyload
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-53890 | pyLoad vulnerable to remote code execution through js2py onCaptchaResult CWE-94 | 9.8 | Critical | 2025-07-14 |
| CVE-2025-7346 | pyLoad 安全漏洞 CWE-281 | 6.2AI | Medium AI | 2025-07-08 |
| CVE-2024-47821 | pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API CWE-78 | 9.1 | Critical | 2024-10-25 |
| CVE-2024-32880 | pyLoad allows upload to arbitrary folder lead to RCE CWE-434 | 9.1 | Critical | 2024-04-26 |
| CVE-2024-24808 | pyLoad open redirect vulnerability due to improper validation of the is_safe_url function CWE-601 | 4.7 | Medium | 2024-02-06 |
| CVE-2024-22416 | Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation CWE-352 | 9.7 | Critical | 2024-01-17 |
| CVE-2024-21644 | pyLoad unauthenticated flask configuration leakage CWE-284 | 7.5 | High | 2024-01-08 |
| CVE-2024-21645 | pyLoad Log Injection CWE-74 | 5.3 | Medium | 2024-01-08 |
All 38 known CVE vulnerabilities affecting pyload with full Chinese analysis, references, and POCs where available.