Lftp is a command-line file-transfer utility that provides FTP, SFTP, and HTTP client functionality for automated scripting and interactive file operations. Observed vulnerabilities center on the product's input-handling layer, with improper input validation recurrently identified as the primary weakness class. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lftp Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10916MEDIUM It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mir | Aug 1, 2018 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lftp Project.
Media articles that mention a CVE ID that affects a product developed by Lftp Project — matched by CVE ID, not by vendor name.