s
sftpgo project
Security Risk Profile
34
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 2, 2022 to present
6
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
34/100
low
Severity Distribution
Critical
0High
2Medium
4Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
2
2
Input Validation
2
3
Race Condition
1
4
Buffer Overflow
1
5
XSS
1
Most Affected Products
1. Fortinet FortiSIEM11
2. Sftpgo Project Sftpgo6
3. Fortinet FortiWeb6
4. Fortinet FortiEDR Manager5
5. Fortinet FortiMail5
Recent Vulnerabilities
See more →CVE-2026-30915
CVSS 5.3EPSS 0%medium
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes
Mar 13, 2026
CVE-2026-30914
CVSS 8.1EPSS 0%high
SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy
Mar 13, 2026
CVE-2024-40430
CVSS 6.5medium
Jul 22, 2024🔧 No Patch
CVE-2023-48795
CVSS 6.0medium
OpenSSH Terrapin attack (CVE-2023-48795)
Dec 12, 2023
CVE-2022-39220
CVSS 6.1medium
XSS Vulnerabilities in WebClient
Sep 20, 2022🔧 No Patch
CVE-2022-36071
CVSS 8.3high
Recovery codes abuse in SFTPGo
Sep 2, 2022
Monitor sftpgo project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.