go

github.com/drakkan/sftpgo/v2

View on go registry
20 Total advisories
20 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.9
Go

CVE-2026-49244

SFTPGo has path confinement bypass in public browsable share partial ZIP download

LOW 3.7
Go

CVE-2026-49245

SFTPGo has stored XSS via inline parameter on public shares and user file download

UNKNOWN
Go

CVE-2026-49244

SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-49245

SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-30915

SFTPGo improperly sanitizes placeholders in group home directories/key prefixes

UNKNOWN
Go

CVE-2026-30914

SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy

UNKNOWN
Go

CVE-2026-30914

SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2026-30915

SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2025-24366

SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-52801

sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-52309

SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2024-37897

SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2022-39220

SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo

UNKNOWN
Go

CVE-2022-36071

SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo

HIGH 7.5
Go

CVE-2025-24366

SFTPGo has insufficient sanitization of user provided rsync command

UNKNOWN
Go

CVE-2024-52801

sftpgo vulnerable to brute force takeover of OpenID Connect session cookies

UNKNOWN
Go

CVE-2024-52309

SFTPGo allows administrators to restrict command execution from the EventManager

HIGH 8.3
Go

CVE-2022-36071

SFTPGo vulnerable to recovery codes abuse

MEDIUM 6.5
Go

GHSA-x72p-g37q-4xr9

Withdrawn: SFTPGo's JWT implmentation lacks certain security measures

MEDIUM 6.5
Go

CVE-2024-37897

SFTPGo has insufficient access control for password reset

Ready to move

Start Securing

Free, no credit card | First findings in minutes