Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sftpgo Project

First CVE: Sep 2, 2022Active for: 4 yearsTotal CVEs: 5

Sftpgo Project maintains a focused file-transfer appliance and server built around SFTP, FTPS, and WebDAV protocols, which concentrates security exposure in a narrowly scoped but widely embedded product. Its durable vulnerability signal reflects the input-handling and access-control demands of a file-serving platform: path-traversal issues, authentication weaknesses, cross-site scripting in web interfaces, integrity-validation gaps, and password-hashing implementation deficiencies recur across the product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sftpgo Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2022
3 years ago
Most Recent CVE
Mar 13, 2026
133 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2026-30914HIGH
SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Vi
Mar 13, 20268.125NONO
CVE-2022-36071HIGH
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secon
Sep 2, 20228.125NONO
CVE-2022-39220MEDIUM
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inje
Sep 20, 20226.122NONO
CVE-2026-30915MEDIUM
SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example,
Mar 13, 20264.317NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sftpgo Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sftpgo Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sftpgo Project's Products

View all 2 CNAs →

Top CWEs