Skip to content
Noroxi

wftpserver records

22 published records for vendor wftpserver.

All records

22 records
  • In Wing FTP Server before 7.4.4.

    CriticalCVSS 10.0KEVWeaponizedEPSS 93%

    wftpserver · wing ftp serverJul 10, 2025

  • CVE-2025-47813
    66This week

    loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI

    MediumCVSS 4.3KEVWeaponizedEPSS 63%

    wftpserver · wing ftp serverJul 10, 2025

  • CVE-2009-0351
    38Monitor

    Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argum

    CriticalCVSS 9.0Proof of conceptEPSS 5%

    wftpserver · winftp ftp serverJan 29, 2009

  • Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serialization

    HighCVSS 8.6Proof of conceptEPSS 2%

    wftpserver · wing ftp serverMay 12, 2026

  • Weak Access Control between Domains in Wing FTP Server <= 7.2.0

    HighCVSS 8.8No exploitEPSS 1%

    wftpserver · wing ftp serverSep 12, 2023

  • Insecure Default Permissions in Wing FTP Server <= 7.2.0

    HighCVSS 8.8No exploitEPSS 1%

    wftpserver · wing ftp serverSep 12, 2023

  • Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection

    HighCVSS 8.8No exploitEPSS 0%

    wftpserver · wing ftp serverJul 10, 2025

  • Wing FTP Server 6.3.8 - Remote Code Execution

    HighCVSS 8.6No exploitEPSS 1%

    wftpserver · wing ftp serverJan 30, 2026

  • Wing FTP Server 6.0.7 - Unquoted Service Path

    HighCVSS 8.5No exploitEPSS 0%

    wftpserver · wing ftp serverFeb 4, 2026

  • CVE-2020-8635
    31Monitor

    Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files.

    HighCVSS 7.8Proof of conceptEPSS 1%

    wftpserver · wing ftp serverMar 6, 2020

  • CVE-2020-9470
    31Monitor

    An issue was discovered in Wing FTP Server 6.2.5 before February 2020.

    HighCVSS 7.8Proof of conceptEPSS 1%

    wftpserver · wing ftp serverMar 6, 2020

  • CVE-2020-8634
    31Monitor

    Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface,

    HighCVSS 7.8No exploitEPSS 0%

    wftpserver · wing ftp serverMar 6, 2020

  • CVE-2025-5196
    30Monitor

    Wing FTP Server Lua Admin Console unnecessary privileges

    HighCVSS 7.5Proof of conceptEPSS 1%

    wftpserver · wing ftp serverMay 26, 2025

  • Exposed Session Variable in Wing FTP Server <= 7.2.0

    HighCVSS 7.5No exploitEPSS 1%

    wftpserver · wing ftp serverSep 12, 2023

  • CVE-2015-4108
    28Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authenticati

    MediumCVSS 6.8No exploitEPSS 2%

    wftpserver · wing ftp serverJun 10, 2015

  • CVE-2012-4729
    28Monitor

    Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.

    MediumCVSS 6.8No exploitEPSS 2%

    wftpserver · wing ftp serverOct 26, 2012

  • In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default.

    MediumCVSS 6.6No exploitEPSS 5%

    wftpserver · wing ftp serverJul 10, 2025

  • An XSS issue was discovered in Wing FTP 6.4.4.

    MediumCVSS 6.1Proof of conceptEPSS 6%

    wftpserver · wing ftp serverJan 26, 2021

  • Cross-Site Scripting Vulnerability in Wing FTP Server <= 7.2.0

    MediumCVSS 5.4No exploitEPSS 0%

    wftpserver · wing ftp serverSep 12, 2023

  • CVE-2008-5666
    20Monitor

    WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence

    LowCVSS 3.5WeaponizedEPSS 21%

    wftpserver · winftp ftp serverDec 18, 2008

  • Wing FTP Server < 6.2.7 - Cross-site Request Forgery

    MediumCVSS 5.1No exploitEPSS 0%

    wftpserver · wing ftp serverFeb 6, 2026

  • CVE-2010-2428
    18Monitor

    Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and e

    MediumCVSS 4.3No exploitEPSS 2%

    wftpserver · wing ftp serverJun 24, 2010