SmartFTP is a file-transfer client focused on a single widely used product that serves users across many environments where FTP, SFTP, and related protocols are deployed. The vendor's vulnerability profile centers on resource-handling and input-validation weaknesses characteristic of client-side file-transfer applications, including path-traversal flaws, memory-buffer management issues, and denial-of-service vectors tied to resource allocation. Disclosed issues have a marked tendency to acquire public exploit tooling; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartftp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0790HIGH Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner. | Feb 6, 2007 | 7.5 | 31 | NO | YES |
CVE-2010-4871HIGH Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename. | Oct 7, 2011 | 10.0 | 29 | NO | NO |
CVE-2021-47791HIGH SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can tri | Jan 16, 2026 | 7.5 | 25 | NO | NO |
CVE-2010-3099HIGH Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary f | Aug 20, 2010 | 9.3 | 25 | NO | NO |
CVE-2018-25234MEDIUM SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field | Mar 30, 2026 | 6.2 | 22 | NO | NO |
CVE-2003-1319HIGH Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which t | Dec 31, 2003 | 7.6 | 21 | NO | NO |
CVE-2010-5219MEDIUM Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrate | Sep 6, 2012 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartftp.
Media articles that mention a CVE ID that affects a product developed by Smartftp — matched by CVE ID, not by vendor name.