Sftpgo Project maintains a focused file-transfer appliance and server built around SFTP, FTPS, and WebDAV protocols, which concentrates security exposure in a narrowly scoped but widely embedded product. Its durable vulnerability signal reflects the input-handling and access-control demands of a file-serving platform: path-traversal issues, authentication weaknesses, cross-site scripting in web interfaces, integrity-validation gaps, and password-hashing implementation deficiencies recur across the product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sftpgo Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2026-30914HIGH SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Vi | Mar 13, 2026 | 8.1 | 25 | NO | NO |
CVE-2022-36071HIGH SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secon | Sep 2, 2022 | 8.1 | 25 | NO | NO |
CVE-2022-39220MEDIUM SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inje | Sep 20, 2022 | 6.1 | 22 | NO | NO |
CVE-2026-30915MEDIUM SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example, | Mar 13, 2026 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sftpgo Project.
Media articles that mention a CVE ID that affects a product developed by Sftpgo Project — matched by CVE ID, not by vendor name.