Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wftpserver

First CVE: Dec 19, 2008Active for: 18 yearsTotal CVEs: 22
72.9
VTI Score
TOP TARGET

Wftpserver maintains a narrow portfolio of FTP server products—Wing FTP Server and WinFTP—that, despite modest volume, occupy a prominent position among file-transfer appliances in the landscape. Vulnerabilities affecting the vendor have a moderate tendency toward confirmed in-the-wild exploitation cataloged by CISA and frequently acquire public exploit tooling, reflecting the appeal of FTP services as targets for access and lateral-movement attacks. The exposure recurs through weakness classes spanning web-interface flaws such as cross-site scripting and cross-site request forgery, memory-safety issues including buffer overflows, and privilege and permission misconfigurations endemic to daemon software running with elevated system access. Defenders should treat updates to these products as moderately urgent, particularly when the servers are internet-reachable or handle sensitive file repositories; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
9.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Wftpserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2008
17 years ago
Most Recent CVE
May 12, 2026
73 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-47812CRITICAL
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be us
Jul 10, 202510.099YESYES
CVE-2025-47813MEDIUM
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Jul 10, 20254.389YESYES
CVE-2026-44403HIGH
Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject
May 12, 20267.240NOYES
CVE-2008-5666LOW
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid
Dec 19, 20083.535NOYES
CVE-2009-0351HIGH
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) chara
Jan 29, 20099.034NOYES
CVE-2020-27735MEDIUM
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary H
Jan 26, 20216.130NOYES
CVE-2020-37032HIGH
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage
Jan 30, 20268.828NONO
CVE-2019-25267HIGH
Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers c
Feb 5, 20267.824NONO
CVE-2025-27889HIGH
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks
Jul 10, 20258.824NONO
CVE-2020-8635HIGH
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FT
Mar 7, 20207.824NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
9%
36%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (18.2%)
Network13 (59.1%)
Unknown5 (22.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (72.7%)
High1 (4.5%)
Unknown5 (22.7%)
User Interaction
None13 (59.1%)
Unknown5 (22.7%)
Required4 (18.2%)
Privileges Required
Low10 (45.5%)
High3 (13.6%)
None4 (18.2%)
Unknown5 (22.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
2 CVEs
9.1% of CVEs· 100th percentile
Metasploit
2 CVEs
9.1% of CVEs· 98th percentile
Nuclei
3 CVEs
13.6% of CVEs· 97th percentile
ExploitDB
4 CVEs
18.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wftpserver.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wftpserver — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wftpserver's Products

View all 4 CNAs →

Top CWEs