Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Projectsend

First CVE: Jan 7, 2015Active for: 12 yearsTotal CVEs: 29
76.3
VTI Score
TOP TARGET

Projectsend is a self-hosted file-sharing and project-collaboration application whose modest product scope belies its concentration in a more prominent segment of the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the application's exposure to unauthenticated and authenticated attackers across its web interface. The recurring weakness classes—including cross-site scripting, path traversal, authorization bypass, and improper authentication—are characteristic of web application input handling and access-control implementation, and the presence of CSV formula injection points to a common overlooked surface in data-export features. These vulnerabilities typically affect deployments that store and manage sensitive project files and team credentials, making patching cycles operationally important for organizations using the platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
3.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Projectsend over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2015
11 years ago
Most Recent CVE
Dec 22, 2025
214 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-11680CRITICAL
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP reques
Nov 26, 20249.898YESYES
CVE-2014-9567HIGH
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a f
Jan 7, 20157.560NOYES
CVE-2023-53980CRITICAL
ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts
Dec 22, 20259.835NONO
CVE-2016-10733CRITICAL
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
Oct 29, 20189.832NONO
CVE-2016-10732CRITICAL
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_*
Oct 29, 20189.831NONO
CVE-2021-40887CRITICAL
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP f
Oct 11, 20219.830NONO
CVE-2016-10734CRITICAL
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
Oct 29, 20189.830NONO
CVE-2016-10731CRITICAL
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with th
Oct 29, 20189.830NONO
CVE-2017-9741CRITICAL
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuratio
Jun 18, 20179.830NONO
CVE-2019-11378HIGH
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potenti
Apr 20, 20198.829NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
41%
31%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (89.7%)
Unknown3 (10.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (89.7%)
High0 (0.0%)
Unknown3 (10.3%)
User Interaction
None16 (55.2%)
Unknown3 (10.3%)
Required10 (34.5%)
Privileges Required
Low6 (20.7%)
High2 (6.9%)
None18 (62.1%)
Unknown3 (10.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
1 CVE
3.4% of CVEs· 99th percentile
Metasploit
2 CVEs
6.9% of CVEs· 98th percentile
Nuclei
1 CVE
3.4% of CVEs· 95th percentile
ExploitDB
3 CVEs
10.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Projectsend.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Projectsend — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Projectsend's Products

View all 4 CNAs →

Top CWEs