VendorsXlightftpdxlight_ftp_serverall versions
Vulnerabilities

Xlightftpd Xlight FTP Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-25681
Xlight FTP Server 3.9.1 SEH Overwrite Buffer Overflow
Published 2026-04-05 · Analyzed
8.6EPSS 0.002
CVE-2024-0737
Xlightftpd Xlight FTP Server Login denial of service
Published 2024-01-19 · Modified
7.51 PoCEPSS 0.042
CVE-2023-53886
Xlight FTP Server 3.9.3.6 Stack Buffer Overflow Vulnerability via Execute Program
Published 2025-12-15 · Analyzed
7.5EPSS 0.004
CVE-2009-4795
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
Published 2010-04-22 · Modified
6.81 PoCEPSS 0.020
CVE-2010-2695
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
Published 2010-07-12 · Modified
6.5EPSS 0.019