Provideserver's vulnerability footprint centers on its Provide FTP Server product, a specialized but notably present file-transfer application that handles user authentication and web-facing administration interfaces. The exposure recurs through application-layer weakness classes including cross-site request forgery, cross-site scripting, path traversal, injection flaws, and improper privilege management—patterns typical of web-accessible server software where input sanitization and access control are critical. Vulnerabilities affecting this vendor skew toward serious outcomes; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Provideserver over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11708CRITICAL An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, | Apr 12, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-11706HIGH An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, admin ones included; C | Apr 12, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-11707HIGH An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-adm | Apr 12, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-11701HIGH An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for upload | Apr 12, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-11703HIGH An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter. | Apr 12, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-11705CRITICAL An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbit | Apr 12, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-11702MEDIUM An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filenam | Apr 12, 2020 | 6.1 | 22 | NO | NO |
CVE-2020-11704MEDIUM An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the gr | Apr 12, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Provideserver.
Media articles that mention a CVE ID that affects a product developed by Provideserver — matched by CVE ID, not by vendor name.