wftpserver records
22 published records for vendor wftpserver.
Researcher profile
- Entered KEV
- 2 · 9.1%
- Weaponized
- 3 · 13.6%
- Pre-auth RCE
- 2
- With a fix record
- 4.5%
- Median publish → KEV
- 127 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-250 Execution with Unnecessary Privileges1
- CWE-267 Privilege Defined With Unsafe Actions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2025-47812Weaponized | In Wing FTP Server before 7.4.4.wftpserver · wing ftp server · CWE-158 | Critical10.0 | KEV | 92.9% | Jul 10, 2025 |
66This week | CVE-2025-47813Weaponized | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UIwftpserver · wing ftp server · CWE-209 | Medium4.3 | KEV | 63.0% | Jul 10, 2025 |
38Monitor | CVE-2009-0351Proof of concept | Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argumwftpserver · winftp ftp server · CWE-119 | Critical9.0 | — | 5.3% | Jan 29, 2009 |
35Monitor | CVE-2026-44403Proof of concept | Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serializationwftpserver · wing ftp server · CWE-94 | High8.6 | — | 2.3% | May 12, 2026 |
35Monitor | CVE-2023-37881No exploit | Weak Access Control between Domains in Wing FTP Server <= 7.2.0wftpserver · wing ftp server · CWE-863 | High8.8 | — | 0.6% | Sep 12, 2023 |
35Monitor | CVE-2023-37878No exploit | Insecure Default Permissions in Wing FTP Server <= 7.2.0wftpserver · wing ftp server · CWE-276 | High8.8 | — | 0.5% | Sep 12, 2023 |
35Monitor | CVE-2025-27889No exploit | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injectionwftpserver · wing ftp server · CWE-15 | High8.8 | — | 0.4% | Jul 10, 2025 |
34Monitor | CVE-2020-37032No exploit | Wing FTP Server 6.3.8 - Remote Code Executionwftpserver · wing ftp server · CWE-78 | High8.6 | — | 1.2% | Jan 30, 2026 |
34Monitor | CVE-2019-25267No exploit | Wing FTP Server 6.0.7 - Unquoted Service Pathwftpserver · wing ftp server · CWE-428 | High8.5 | — | 0.2% | Feb 4, 2026 |
31Monitor | CVE-2020-8635Proof of concept | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files.wftpserver · wing ftp server · CWE-732 | High7.8 | — | 0.8% | Mar 6, 2020 |
31Monitor | CVE-2020-9470Proof of concept | An issue was discovered in Wing FTP Server 6.2.5 before February 2020.wftpserver · wing ftp server · CWE-732 | High7.8 | — | 0.6% | Mar 6, 2020 |
31Monitor | CVE-2020-8634No exploit | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, wftpserver · wing ftp server · CWE-281 | High7.8 | — | 0.4% | Mar 6, 2020 |
30Monitor | CVE-2025-5196Proof of concept | Wing FTP Server Lua Admin Console unnecessary privilegeswftpserver · wing ftp server · CWE-250 | High7.5 | — | 1.0% | May 26, 2025 |
30Monitor | CVE-2023-37879No exploit | Exposed Session Variable in Wing FTP Server <= 7.2.0wftpserver · wing ftp server · CWE-922 | High7.5 | — | 0.5% | Sep 12, 2023 |
28Monitor | CVE-2015-4108No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authenticatiwftpserver · wing ftp server · CWE-352 | Medium6.8 | — | 2.4% | Jun 10, 2015 |
28Monitor | CVE-2012-4729No exploit | Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.wftpserver · wing ftp server · CWE-119 | Medium6.8 | — | 2.2% | Oct 26, 2012 |
27Monitor | CVE-2025-47811No exploit | In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default.wftpserver · wing ftp server · CWE-267 | Medium6.6 | — | 4.8% | Jul 10, 2025 |
26Monitor | CVE-2020-27735Proof of concept | An XSS issue was discovered in Wing FTP 6.4.4.wftpserver · wing ftp server · CWE-79 | Medium6.1 | — | 5.8% | Jan 26, 2021 |
21Monitor | CVE-2023-37875No exploit | Cross-Site Scripting Vulnerability in Wing FTP Server <= 7.2.0wftpserver · wing ftp server · CWE-116 | Medium5.4 | — | 0.3% | Sep 12, 2023 |
20Monitor | CVE-2008-5666Weaponized | WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequencewftpserver · winftp ftp server · CWE-399 | Low3.5 | — | 20.6% | Dec 18, 2008 |
20Monitor | CVE-2020-37079No exploit | Wing FTP Server < 6.2.7 - Cross-site Request Forgerywftpserver · wing ftp server · CWE-352 | Medium5.1 | — | 0.2% | Feb 6, 2026 |
18Monitor | CVE-2010-2428No exploit | Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and ewftpserver · wing ftp server · CWE-79 | Medium4.3 | — | 2.0% | Jun 24, 2010 |
- CVE-2025-4781298Now
In Wing FTP Server before 7.4.4.
CriticalCVSS 10.0KEVWeaponizedEPSS 93%wftpserver · wing ftp serverJul 10, 2025
- CVE-2025-4781366This week
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI
MediumCVSS 4.3KEVWeaponizedEPSS 63%wftpserver · wing ftp serverJul 10, 2025
- CVE-2009-035138Monitor
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argum
CriticalCVSS 9.0Proof of conceptEPSS 5%wftpserver · winftp ftp serverJan 29, 2009
- CVE-2026-4440335Monitor
Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serialization
HighCVSS 8.6Proof of conceptEPSS 2%wftpserver · wing ftp serverMay 12, 2026
- CVE-2023-3788135Monitor
Weak Access Control between Domains in Wing FTP Server <= 7.2.0
HighCVSS 8.8No exploitEPSS 1%wftpserver · wing ftp serverSep 12, 2023
- CVE-2023-3787835Monitor
Insecure Default Permissions in Wing FTP Server <= 7.2.0
HighCVSS 8.8No exploitEPSS 1%wftpserver · wing ftp serverSep 12, 2023
- CVE-2025-2788935Monitor
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection
HighCVSS 8.8No exploitEPSS 0%wftpserver · wing ftp serverJul 10, 2025
- CVE-2020-3703234Monitor
Wing FTP Server 6.3.8 - Remote Code Execution
HighCVSS 8.6No exploitEPSS 1%wftpserver · wing ftp serverJan 30, 2026
- CVE-2019-2526734Monitor
Wing FTP Server 6.0.7 - Unquoted Service Path
HighCVSS 8.5No exploitEPSS 0%wftpserver · wing ftp serverFeb 4, 2026
- CVE-2020-863531Monitor
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files.
HighCVSS 7.8Proof of conceptEPSS 1%wftpserver · wing ftp serverMar 6, 2020
- CVE-2020-947031Monitor
An issue was discovered in Wing FTP Server 6.2.5 before February 2020.
HighCVSS 7.8Proof of conceptEPSS 1%wftpserver · wing ftp serverMar 6, 2020
- CVE-2020-863431Monitor
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface,
HighCVSS 7.8No exploitEPSS 0%wftpserver · wing ftp serverMar 6, 2020
- CVE-2025-519630Monitor
Wing FTP Server Lua Admin Console unnecessary privileges
HighCVSS 7.5Proof of conceptEPSS 1%wftpserver · wing ftp serverMay 26, 2025
- CVE-2023-3787930Monitor
Exposed Session Variable in Wing FTP Server <= 7.2.0
HighCVSS 7.5No exploitEPSS 1%wftpserver · wing ftp serverSep 12, 2023
- CVE-2015-410828Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authenticati
MediumCVSS 6.8No exploitEPSS 2%wftpserver · wing ftp serverJun 10, 2015
- CVE-2012-472928Monitor
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
MediumCVSS 6.8No exploitEPSS 2%wftpserver · wing ftp serverOct 26, 2012
- CVE-2025-4781127Monitor
In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default.
MediumCVSS 6.6No exploitEPSS 5%wftpserver · wing ftp serverJul 10, 2025
- CVE-2020-2773526Monitor
An XSS issue was discovered in Wing FTP 6.4.4.
MediumCVSS 6.1Proof of conceptEPSS 6%wftpserver · wing ftp serverJan 26, 2021
- CVE-2023-3787521Monitor
Cross-Site Scripting Vulnerability in Wing FTP Server <= 7.2.0
MediumCVSS 5.4No exploitEPSS 0%wftpserver · wing ftp serverSep 12, 2023
- CVE-2008-566620Monitor
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence
LowCVSS 3.5WeaponizedEPSS 21%wftpserver · winftp ftp serverDec 18, 2008
- CVE-2020-3707920Monitor
Wing FTP Server < 6.2.7 - Cross-site Request Forgery
MediumCVSS 5.1No exploitEPSS 0%wftpserver · wing ftp serverFeb 6, 2026
- CVE-2010-242818Monitor
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and e
MediumCVSS 4.3No exploitEPSS 2%wftpserver · wing ftp serverJun 24, 2010