Projectsend is a self-hosted file-sharing and project-collaboration application whose modest product scope belies its concentration in a more prominent segment of the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the application's exposure to unauthenticated and authenticated attackers across its web interface. The recurring weakness classes—including cross-site scripting, path traversal, authorization bypass, and improper authentication—are characteristic of web application input handling and access-control implementation, and the presence of CSV formula injection points to a common overlooked surface in data-export features. These vulnerabilities typically affect deployments that store and manage sensitive project files and team credentials, making patching cycles operationally important for organizations using the platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectsend over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11680CRITICAL ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP reques | Nov 26, 2024 | 9.8 | 98 | YES | YES |
CVE-2014-9567HIGH Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a f | Jan 7, 2015 | 7.5 | 60 | NO | YES |
CVE-2023-53980CRITICAL ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts | Dec 22, 2025 | 9.8 | 35 | NO | NO |
CVE-2016-10733CRITICAL ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. | Oct 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2016-10732CRITICAL ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-40887CRITICAL Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP f | Oct 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2016-10734CRITICAL ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. | Oct 29, 2018 | 9.8 | 30 | NO | NO |
CVE-2016-10731CRITICAL ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with th | Oct 29, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-9741CRITICAL install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuratio | Jun 18, 2017 | 9.8 | 30 | NO | NO |
CVE-2019-11378HIGH An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potenti | Apr 20, 2019 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectsend.
Media articles that mention a CVE ID that affects a product developed by Projectsend — matched by CVE ID, not by vendor name.