20 Total advisories
20 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.9
CVE-2026-49244
SFTPGo has path confinement bypass in public browsable share partial ZIP download
LOW 3.7
CVE-2026-49245
SFTPGo has stored XSS via inline parameter on public shares and user file download
UNKNOWN
CVE-2026-49244
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo
UNKNOWN
CVE-2026-49245
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo
UNKNOWN
CVE-2026-30915
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes
UNKNOWN
CVE-2026-30914
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
UNKNOWN
CVE-2026-30914
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo
UNKNOWN
CVE-2026-30915
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo
UNKNOWN
CVE-2025-24366
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo
UNKNOWN
CVE-2024-52801
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo
UNKNOWN
CVE-2024-52309
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo
UNKNOWN
CVE-2024-37897
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo
UNKNOWN
CVE-2022-39220
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo
UNKNOWN
CVE-2022-36071
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo
HIGH 7.5
CVE-2025-24366
SFTPGo has insufficient sanitization of user provided rsync command
UNKNOWN
CVE-2024-52801
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies
UNKNOWN
CVE-2024-52309
SFTPGo allows administrators to restrict command execution from the EventManager
HIGH 8.3
CVE-2022-36071
SFTPGo vulnerable to recovery codes abuse
MEDIUM 6.5
GHSA-x72p-g37q-4xr9
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures
MEDIUM 6.5
CVE-2024-37897
SFTPGo has insufficient access control for password reset
Ready to move
Start Securing
Free, no credit card | First findings in minutes