Vendor
pyLoad vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in pyLoad: 0 in the last 7 days and 2 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48987, was published on 15 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 3
- Exploited in the wild
- 0
About pyLoad
The developer of pyLoad, an open-source download manager written in Python.
pyLoad technologies
Latest pyLoad vulnerabilities
- CVE-2026-48987: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-48737: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in…mediumCVSS 4.9EPSS 0.3%
- CVE-2026-46561: pyLoad SSRF via HTTP redirect bypass in parse_urls APImediumCVSS 5EPSS 0.3%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
- CVE-2026-45306: pyLoad account takeover via session directory bypass in storage_foldermediumCVSS 6.5EPSS 0.4%
- CVE-2026-44226: pyLoad pyload-ng information disclosure in WebUI error handlermediumCVSS 5.3EPSS 0.4%
- CVE-2026-42315: pyLoad path traversal in set_package_data APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-42314: pyLoad path traversal in package folder name sanitizationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-42313: pyLoad incorrect authorization in proxy configuration settingshighCVSS 8.3EPSS 0.4%
- CVE-2026-42312: pyLoad improper authorization allows disabling TLS verificationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-40594: pyLoad session cookie security downgrade via header spoofingmediumCVSS 4.8EPSS 0.2%
- pyLoad insufficient session expiration after permission changeslowCVSS 2.9
- CVE-2026-40071: pyload-ng improper authorization in WebUI JSON endpointsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-35592: pyload-ng path traversal in UnTar extractionmediumCVSS 5.3EPSS 0.4%
- CVE-2026-35586: pyload-ng authorization bypass in SSL configurationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-35459: pyLoad SSRF via HTTP redirect bypass in BaseDownloadercriticalCVSS 9.1EPSS 0.4%
- CVE-2026-35187: pyLoad SSRF and local file disclosure in parse_urls APIhighCVSS 7.7EPSS 0.4%
- CVE-2026-33314: pyload-ng auth bypass via Host header spoofing in Click'N'Load APImediumCVSS 6.5EPSS 0.2%
- CVE-2026-29778: pyLoad path traversal in edit_packagehighCVSS 7.1EPSS 0.5%
- CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_checkhighCVSS 7.5EPSS 0.3%
- pyload-ng localhost restriction bypass allowing arbitrary package creationmediumCVSS 4
- pyload-ng RCE via js2py sandbox escapeinfoCVSS 9.8
- CVE-2024-47821: pyLoad remote code execution via flashgot API and scripts folder manipulationcriticalCVSS 9.1EPSS 0.7%
- CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalationcriticalCVSS 9.6EPSS 0.9%
Most severe pyLoad vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalationcriticalCVSS 9.6EPSS 0.9%
- CVE-2024-47821: pyLoad remote code execution via flashgot API and scripts folder manipulationcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-35459: pyLoad SSRF via HTTP redirect bypass in BaseDownloadercriticalCVSS 9.1EPSS 0.4%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
- CVE-2026-42313: pyLoad incorrect authorization in proxy configuration settingshighCVSS 8.3EPSS 0.4%
- CVE-2026-42315: pyLoad path traversal in set_package_data APIhighCVSS 8.1EPSS 0.5%
- CVE-2026-35187: pyLoad SSRF and local file disclosure in parse_urls APIhighCVSS 7.7EPSS 0.4%
- CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_checkhighCVSS 7.5EPSS 0.3%
- CVE-2026-29778: pyLoad path traversal in edit_packagehighCVSS 7.1EPSS 0.5%
- CVE-2026-42312: pyLoad improper authorization allows disabling TLS verificationmediumCVSS 6.8EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/pyload.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pyLoad vulnerabilities", https://junglewise.ai/threats/vendors/pyload, 26 September 2026.