CVE security advisories and vulnerability history for pillow by PyPI.
51
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
0
Public exploits
With known exploit
8.1
Avg CVSS
2014–2025
Last updated
Overview
PyPI pillow has 51 published CVE records since 2014, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 0 have a known public exploit. The average CVSS base score across scored CVEs is 8.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting PyPI pillow, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of PyPI pillow's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High2
Medium0
Low0
48 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of PyPI pillow's CVEs are currently listed in CISA's KEV catalog.
Public exploits
0
No PyPI pillow CVEs currently have a tracked public exploit.
Affected versions and CVEs
Browse every PyPI pillow version named in a CVE, then pick one to see only the CVEs that affect it.