Wing Ftp Server

Vendor:

First CVE: Jun 24, 2010 · Active for 16 years

20
Total CVEs
More Total CVEs than 94% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Wing Ftp Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2010
16 years ago
Most Recent CVE
May 12, 2026
73 days ago

CVE Severity & Scoring

Wing Ftp Server20 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local4 (20.0%)
Network13 (65.0%)
Unknown3 (15.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (80.0%)
High1 (5.0%)
Unknown3 (15.0%)
User Interaction
None13 (65.0%)
Unknown3 (15.0%)
Required4 (20.0%)
Privileges Required
Low10 (50.0%)
High3 (15.0%)
None4 (20.0%)
Unknown3 (15.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be us
Jul 10, 202510.099YESYES
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Jul 10, 20254.389YESYES
Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject
May 12, 20267.240NOYES
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary H
Jan 26, 20216.130NOYES
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage
Jan 30, 20268.828NONO
Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers c
Feb 5, 20267.824NONO
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks
Jul 10, 20258.824NONO
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FT
Mar 7, 20207.824NONO
Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
Sep 12, 20238.823NONO
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
Sep 12, 20238.823NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
2 CVEs
10.0% of CVEs· 97th percentile
Metasploit
1 CVE
5.0% of CVEs· 97th percentile
Nuclei
3 CVEs
15.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
10.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Wing Ftp Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.4.416.15.6%01
6.3.818.81.0%00
6.2.327.80.6%00
6.0.717.80.2%00
4.0.816.82.2%00
4.0.616.82.2%00
4.0.516.82.2%00
4.0.316.82.2%00
4.0.216.82.2%00
4.0.116.82.2%00
3.8.916.82.2%00
3.8.816.82.2%00
3.8.716.82.2%00
3.8.616.82.2%00
3.8.516.82.2%00
3.8.016.82.2%00
3.7.516.82.2%00
3.7.216.82.2%00
3.6.816.82.2%00
3.6.616.82.2%00