VendorsProgressmoveit_transferany version
Vulnerabilities

Progress MOVEit Transfer any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.
Published 2023-06-02 · Analyzed
9.8KEVEPSS 0.999
CVE-2023-35708
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).
Published 2023-06-16 · Modified
9.8EPSS 0.967
CVE-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability
Published 2024-06-25 · Analyzed
9.8EPSS 0.815
CVE-2021-38159
In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Transfer transaction types. The fixed versions are 2019.0.8 (11.0.8), 2019.1.7 (11.1.7), 2019.2.4 (11.2.4), 2020.0.7 (12.0.7), 2020.1.6 (12.1.6), and 2021.0.4 (13.0.4).
Published 2021-08-07 · Modified
9.8EPSS 0.019
CVE-2024-6576
MOVEit Transfer Privilege Escalation Vulnerability
Published 2024-07-29 · Analyzed
9.8EPSS 0.006
CVE-2026-8801
File Extension Restriction Bypass in MOVEit Transfer
Published 2026-07-08 · Analyzed
9.8EPSS 0.003
CVE-2026-10697
MFA Bypass in MOVEit Transfer
Published 2026-07-23 · Analyzed
9.8EPSS 0.003
CVE-2026-8649
Institution scope bypass vulnerability in custom reports
Published 2026-07-08 · Analyzed
9.8EPSS 0.003
CVE-2026-15967
MOVEit Transfer refresh-token processing does not enforce updated account restrictions
Published 2026-07-23 · Analyzed
9.8EPSS 0.002
CVE-2026-15966
Improper CORS handling in MOVEit Transfer
Published 2026-07-23 · Analyzed
9.8EPSS 0.002
CVE-2023-36934
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
Published 2023-07-05 · Modified
9.1EPSS 0.952
CVE-2023-35036
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
Published 2023-06-12 · Modified
9.1EPSS 0.128
CVE-2020-8612
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
Published 2020-02-14 · Modified
9.0EPSS 0.017
CVE-2021-37614
In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Transfer transaction types. The fixed versions are 2019.0.7 (11.0.7), 2019.1.6 (11.1.6), 2019.2.3 (11.2.3), 2020.0.6 (12.0.6), 2020.1.5 (12.1.5), and 2021.0.3 (13.0.3).
Published 2021-08-05 · Modified
8.8EPSS 0.015
CVE-2020-8611
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements.
Published 2020-02-14 · Modified
8.8EPSS 0.012
CVE-2021-31827
In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements. This is in MOVEit.DMZ.WebApp in SILHuman.vb.
Published 2021-05-18 · Modified
8.8EPSS 0.012
CVE-2021-33894
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow an authenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and/or execute SQL statements that alter or delete database elements.
Published 2021-06-09 · Modified
8.8EPSS 0.011
CVE-2023-42660
MOVEit Transfer Machine Interface SQL Injection
Published 2023-09-20 · Modified
8.8EPSS 0.007
CVE-2025-2324
A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folder
Published 2025-03-19 · Analyzed
8.8EPSS 0.003
CVE-2026-8800
Cross-Org External Token Metadata accessible to AuditUser role
Published 2026-07-08 · Analyzed
8.8EPSS 0.002
CVE-2023-36932
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
Published 2023-07-05 · Modified
8.1EPSS 0.811
CVE-2026-11903
Stored XSS in MOVEit Transfer Ad Hoc module
Published 2026-07-08 · Analyzed
8.0EPSS 0.004
CVE-2023-36933
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
Published 2023-07-05 · Modified
7.5EPSS 0.722
CVE-2026-10699
Memory leak in SFTP service can result in a denial of service in MOVEit Transfer
Published 2026-07-08 · Analyzed
7.5EPSS 0.005
CVE-2026-8651
IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer
Published 2026-07-08 · Analyzed
7.5EPSS 0.004
CVE-2026-8650
Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
Published 2026-07-08 · Analyzed
7.5EPSS 0.004
CVE-2025-11235
MOVEit Transfer REST API does not require current password in order to initiate the password change process
Published 2026-01-06 · Analyzed
7.5EPSS 0.002
CVE-2023-6218
MOVEit Transfer Group Admin Privilege Escalation
Published 2023-11-29 · Modified
7.2EPSS 0.007
CVE-2023-40043
MOVEit Transfer System Administrator SQL Injection
Published 2023-09-20 · Modified
7.2EPSS 0.007
CVE-2026-10698
Table scope bypass vulnerability in custom reports
Published 2026-07-08 · Analyzed
7.2EPSS 0.006
CVE-2024-0396
Missing Server-Side Input Validation in HTTP Parameter
Published 2024-01-17 · Modified
7.1EPSS 0.005
CVE-2023-6217
MOVEit Transfer XSS via MOVEit Gateway
Published 2023-11-29 · Modified
7.1EPSS 0.005
CVE-2026-15968
Stored XSS vulnerability in MOVEit Transfer
Published 2026-07-23 · Analyzed
7.1EPSS 0.002
CVE-2023-42656
MOVEit Transfer Reflected XSS
Published 2023-09-20 · Modified
6.1EPSS 0.006
CVE-2020-28647
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Published 2020-11-17 · Modified
5.4EPSS 0.015
CVE-2025-13147
External Service Interaction (DNS)
Published 2025-11-19 · Analyzed
5.3EPSS 0.003
CVE-2024-2291
MOVEit Transfer Logging Bypass Vulnerability
Published 2024-03-20 · Analyzed
4.3EPSS 0.004