| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-30915 | SFTPGo improperly sanitizes placeholders in group home directories/key prefixes | drakkan | sftpgo | 中危 | - | 2026-03-13 19:04:37 | Deep Dive |
| CVE-2026-30914 | SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy | drakkan | sftpgo | 中危 | - | 2026-03-13 19:02:28 | Deep Dive |
| CVE-2025-24366 | Insufficient sanitization of user provided rsync command in SFTPGo | drakkan | sftpgo | High | 7.5 | 2025-02-07 21:16:40 | Deep Dive |
| CVE-2024-52801 | Brute force takeover of OpenID Connect session cookies in sftpgo | drakkan | sftpgo | 中危 | - | 2024-11-29 18:26:06 | Deep Dive |
| CVE-2024-52309 | SFTPGo allows administrators to restrict command execution from the EventManager | drakkan | sftpgo | - | - | 2024-11-21 17:11:07 | Deep Dive |
| CVE-2024-37897 | Insufficient access control for password reset in sftpgo | drakkan | sftpgo | Medium | 5.4 | 2024-06-20 17:32:53 | Deep Dive |
| CVE-2022-39220 | XSS Vulnerabilities in WebClient | drakkan | sftpgo | Medium | 6.1 | 2022-09-20 22:10:08 | Deep Dive |
| CVE-2022-36071 | Recovery codes abuse in SFTPGo | drakkan | sftpgo | High | 8.3 | 2022-09-02 17:15:12 | Deep Dive |