ProFTPD is a widely deployed open-source FTP server that occupies a prominent position in the vulnerability landscape despite a narrow product scope, reflecting its deep integration across hosting infrastructure, content-delivery networks, and legacy systems. The vendor's disclosures recur around memory-safety and input-handling defects—including buffer-boundary violations, SQL injection, and cross-site request forgery—that are characteristic of network daemons, and frequently acquire public exploit code. Defenders should track this vendor's advisories closely and prioritize patching internet-exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Proftpd Project over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3306HIGH The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | May 18, 2015 | 10.0 | 93 | NO | YES |
CVE-2010-4221HIGH Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involvin | Nov 9, 2010 | 10.0 | 90 | NO | YES |
CVE-2006-5815HIGH Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrar | Nov 8, 2006 | 10.0 | 82 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2009-0542HIGH SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which | Feb 12, 2009 | 7.5 | 71 | NO | YES |
CVE-2003-0831HIGH ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a b | Nov 17, 2003 | 9.0 | 66 | NO | YES |
CVE-2019-12815CRITICAL An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE- | Jul 19, 2019 | 9.8 | 63 | NO | NO |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-1999-0911HIGH Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Aug 27, 1999 | 10.0 | 56 | NO | YES |
CVE-2026-42167HIGH mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U | Apr 28, 2026 | 8.1 | 54 | NO | YES |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Proftpd Project.
Media articles that mention a CVE ID that affects a product developed by Proftpd Project — matched by CVE ID, not by vendor name.