Skip to main content

Vendor/product archive

sftpgo_project / sftpgo CVEs

Beta · best-effort

4 CVEs tagged to sftpgo_project / sftpgo0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-30915

Published Mar 13, 2026

SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example,…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30914

Published Mar 13, 2026

SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal V…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-39220

Published Sep 20, 2022

SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inj…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36071

Published Sep 2, 2022

SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a seco…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1