Wftpserver maintains a narrow portfolio of FTP server products—Wing FTP Server and WinFTP—that, despite modest volume, occupy a prominent position among file-transfer appliances in the landscape. Vulnerabilities affecting the vendor have a moderate tendency toward confirmed in-the-wild exploitation cataloged by CISA and frequently acquire public exploit tooling, reflecting the appeal of FTP services as targets for access and lateral-movement attacks. The exposure recurs through weakness classes spanning web-interface flaws such as cross-site scripting and cross-site request forgery, memory-safety issues including buffer overflows, and privilege and permission misconfigurations endemic to daemon software running with elevated system access. Defenders should treat updates to these products as moderately urgent, particularly when the servers are internet-reachable or handle sensitive file repositories; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wftpserver over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47812CRITICAL In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be us | Jul 10, 2025 | 10.0 | 99 | YES | YES |
CVE-2025-47813MEDIUM loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Jul 10, 2025 | 4.3 | 89 | YES | YES |
CVE-2026-44403HIGH Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject | May 12, 2026 | 7.2 | 40 | NO | YES |
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid | Dec 19, 2008 | 3.5 | 35 | NO | YES |
CVE-2009-0351HIGH Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) chara | Jan 29, 2009 | 9.0 | 34 | NO | YES |
CVE-2020-27735MEDIUM An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary H | Jan 26, 2021 | 6.1 | 30 | NO | YES |
CVE-2020-37032HIGH Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage | Jan 30, 2026 | 8.8 | 28 | NO | NO |
CVE-2019-25267HIGH Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers c | Feb 5, 2026 | 7.8 | 24 | NO | NO |
CVE-2025-27889HIGH Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks | Jul 10, 2025 | 8.8 | 24 | NO | NO |
CVE-2020-8635HIGH Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FT | Mar 7, 2020 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wftpserver.
Media articles that mention a CVE ID that affects a product developed by Wftpserver — matched by CVE ID, not by vendor name.