VendorsFortragoanywhere_managed_file_transferany version
Vulnerabilities

Fortra Goanywhere Managed File Transfer any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2025-10035
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
Published 2025-09-18 · Analyzed
10.0KEVEPSS 0.998
CVE-2024-0204
Authentication Bypass in GoAnywhere MFT
Published 2024-01-22 · Modified
9.81 PoCEPSS 0.951
CVE-2025-14362
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
Published 2026-04-21 · Analyzed
7.3EPSS 0.002
CVE-2023-0669
Fortra GoAnywhere MFT License Response Servlet Command Injection
Published 2023-02-06 · Analyzed
7.2KEV1 PoCEPSS 1.000
CVE-2024-25157
Authentication bypass in GoAnywhere MFT prior to 7.6.0
Published 2024-08-14 · Analyzed
6.5EPSS 0.005
CVE-2024-25156
Path traversal in GoAnywhere MFT 7.4.1 and Earlier
Published 2024-03-14 · Analyzed
6.5EPSS 0.004
CVE-2026-1089
User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups
Published 2026-04-21 · Analyzed
6.5EPSS 0.002
CVE-2024-11922
Input Validation vulnerability in Web Client emails that do not go through Secure Mail
Published 2025-04-28 · Analyzed
6.3EPSS 0.002
CVE-2025-1241
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Published 2026-04-21 · Analyzed
5.8EPSS 0.001
CVE-2026-0972
HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT
Published 2026-04-21 · Modified
5.4EPSS 0.002
CVE-2025-0049
Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0
Published 2025-04-28 · Analyzed
4.3EPSS 0.003
CVE-2026-0971
GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
Published 2026-04-21 · Analyzed
4.3EPSS 0.002
CVE-2025-8148
CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Published 2025-12-05 · Analyzed
4.2EPSS 0.002