Wing Ftp Server
Vendor:
First CVE: Jun 24, 2010 · Active for 16 years
20
Total CVEs
More Total CVEs than 94% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Wing Ftp Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2010
16 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Wing Ftp Server20 CVEs
40%
50%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (20.0%)
Network13 (65.0%)
Unknown3 (15.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (80.0%)
High1 (5.0%)
Unknown3 (15.0%)
User Interaction
None13 (65.0%)
Unknown3 (15.0%)
Required4 (20.0%)
Privileges Required
Low10 (50.0%)
High3 (15.0%)
None4 (20.0%)
Unknown3 (15.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47812CRITICAL In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be us | Jul 10, 2025 | 10.0 | 99 | YES | YES |
CVE-2025-47813MEDIUM loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Jul 10, 2025 | 4.3 | 89 | YES | YES |
CVE-2026-44403HIGH Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject | May 12, 2026 | 7.2 | 40 | NO | YES |
CVE-2020-27735MEDIUM An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary H | Jan 26, 2021 | 6.1 | 30 | NO | YES |
CVE-2020-37032HIGH Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage | Jan 30, 2026 | 8.8 | 28 | NO | NO |
CVE-2019-25267HIGH Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers c | Feb 5, 2026 | 7.8 | 24 | NO | NO |
CVE-2025-27889HIGH Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks | Jul 10, 2025 | 8.8 | 24 | NO | NO |
CVE-2020-8635HIGH Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FT | Mar 7, 2020 | 7.8 | 24 | NO | NO |
CVE-2023-37881HIGH Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
| Sep 12, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-37878HIGH Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
| Sep 12, 2023 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
2 CVEs
10.0% of CVEs· 97th percentile
Metasploit
1 CVE
5.0% of CVEs· 97th percentile
Nuclei
3 CVEs
15.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Wing Ftp Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4.4 | 1 | 6.1 | 5.6% | 0 | 1 |
| 6.3.8 | 1 | 8.8 | 1.0% | 0 | 0 |
| 6.2.3 | 2 | 7.8 | 0.6% | 0 | 0 |
| 6.0.7 | 1 | 7.8 | 0.2% | 0 | 0 |
| 4.0.8 | 1 | 6.8 | 2.2% | 0 | 0 |
| 4.0.6 | 1 | 6.8 | 2.2% | 0 | 0 |
| 4.0.5 | 1 | 6.8 | 2.2% | 0 | 0 |
| 4.0.3 | 1 | 6.8 | 2.2% | 0 | 0 |
| 4.0.2 | 1 | 6.8 | 2.2% | 0 | 0 |
| 4.0.1 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.9 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.8 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.7 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.6 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.5 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.8.0 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.7.5 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.7.2 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.6.8 | 1 | 6.8 | 2.2% | 0 | 0 |
| 3.6.6 | 1 | 6.8 | 2.2% | 0 | 0 |