ProFTPD is a widely deployed open-source FTP server that, despite a narrow product footprint, occupies a prominent position in the vulnerability landscape due to its use across internet-facing file-transfer infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity and frequently acquire public exploit code, making patching urgent for exposed instances. The recurring exposure centers on memory-safety and input-handling weaknesses including buffer boundary violations, use-after-free conditions, NULL-pointer dereferences, and out-of-bounds reads, alongside improper certificate validation that reflects the parsing demands of the FTP protocol and TLS integration. Defenders should inventory ProFTPD deployments on internet-facing systems and treat its advisories as high-priority; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Proftpd over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3306HIGH The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | May 18, 2015 | 10.0 | 93 | NO | YES |
CVE-2010-4221HIGH Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involvin | Nov 9, 2010 | 10.0 | 90 | NO | YES |
CVE-2006-5815HIGH Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrar | Nov 8, 2006 | 10.0 | 82 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2009-0542HIGH SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which | Feb 12, 2009 | 7.5 | 71 | NO | YES |
CVE-2003-0831HIGH ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a b | Nov 17, 2003 | 9.0 | 66 | NO | YES |
CVE-2019-12815CRITICAL An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE- | Jul 19, 2019 | 9.8 | 63 | NO | NO |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-1999-0911HIGH Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Aug 27, 1999 | 10.0 | 56 | NO | YES |
CVE-2026-42167HIGH mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U | Apr 28, 2026 | 8.1 | 54 | NO | YES |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Proftpd.
Media articles that mention a CVE ID that affects a product developed by Proftpd — matched by CVE ID, not by vendor name.