go

github.com/drakkan/sftpgo

View on go registry
13 Total advisories
13 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
Go

CVE-2026-49244

SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-49245

SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-30914

SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy

UNKNOWN
Go

CVE-2026-30914

SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-30915

SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2025-24366

SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-52801

sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-52309

SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-37897

SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2022-39220

SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2022-36071

SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo

HIGH 7.5
Go

CVE-2025-24366

SFTPGo has insufficient sanitization of user provided rsync command

MEDIUM 6.1
Go

CVE-2022-39220

SFTPGo WebClient vulnerable to Cross-site Scripting

Ready to move

Start Securing

Free, no credit card | First findings in minutes