VYPR

Pydio Cells

by Ajaxplorer

CVEs (2)

  • CVE-2010-10013CriAug 8, 2025
    risk 0.70cvss epss 0.78

    An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer…

  • CVE-2019-15032Sep 19, 2019
    risk 0.00cvss epss 0.00

    Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal…