wftpserver Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for wftpserver products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
2
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
wftpserver KEVs Added by Year
Loading...
2 wftpserver KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-47813
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. |
Wing FTP Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into... |
Wing FTP Server | Confirmed | In CISA | 01 Jun 2026 |
Common Vulnerability Classes (CWE)
- CWE-158 — Improper Neutralization of Null Byte or NUL Character 1
- CWE-209 — Generation of Error Message Containing Sensitive Information 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology