wftpserver Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for wftpserver products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

2

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

wftpserver KEVs Added by Year

Loading...

2 wftpserver KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-47813

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Confirmed In CISA 01 Jun 2026
CVE-2025-47812

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into...

Confirmed In CISA 01 Jun 2026

Common Vulnerability Classes (CWE)

  • CWE-158 — Improper Neutralization of Null Byte or NUL Character 1
  • CWE-209 — Generation of Error Message Containing Sensitive Information 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology