Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Proftpd

First CVE: Feb 9, 1999Active for: 27 yearsTotal CVEs: 54
62.0
VTI Score
TOP TARGET

ProFTPD is a widely deployed open-source FTP server that, despite a narrow product footprint, occupies a prominent position in the vulnerability landscape due to its use across internet-facing file-transfer infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity and frequently acquire public exploit code, making patching urgent for exposed instances. The recurring exposure centers on memory-safety and input-handling weaknesses including buffer boundary violations, use-after-free conditions, NULL-pointer dereferences, and out-of-bounds reads, alongside improper certificate validation that reflects the parsing demands of the FTP protocol and TLS integration. Defenders should inventory ProFTPD deployments on internet-facing systems and treat its advisories as high-priority; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
53
Total CVEs
More Total CVEs than 98% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Proftpd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 1999
27 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-3306HIGH
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
May 18, 201510.093NOYES
CVE-2010-4221HIGH
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involvin
Nov 9, 201010.090NOYES
CVE-2006-5815HIGH
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrar
Nov 8, 200610.082NOYES
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2009-0542HIGH
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which
Feb 12, 20097.571NOYES
CVE-2003-0831HIGH
ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a b
Nov 17, 20039.066NOYES
CVE-2019-12815CRITICAL
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-
Jul 19, 20199.863NONO
CVE-1999-0368HIGH
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
CVE-1999-0911HIGH
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
Aug 27, 199910.056NOYES
CVE-2026-42167HIGH
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U
Apr 28, 20268.154NOYES
View all 53 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products53 CVEs
34%
60%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.8%)
Network19 (35.8%)
Unknown32 (60.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (32.1%)
High4 (7.5%)
Unknown32 (60.4%)
User Interaction
None21 (39.6%)
Unknown32 (60.4%)
Required0 (0.0%)
Privileges Required
Low7 (13.2%)
High1 (1.9%)
None13 (24.5%)
Unknown32 (60.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (53 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
7.5% of CVEs· 98th percentile
Nuclei
7 CVEs
13.2% of CVEs· 97th percentile
ExploitDB
14 CVEs
26.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Proftpd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Proftpd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Proftpd's Products

View all 3 CNAs →

Top CWEs