VYPR
Vendor

Fortra

Products
21
CVEs
39
Across products
68
Status
Private

Products

21

Recent CVEs

39
View all 39 CVEs →
  • CVE-2025-10035CriKEVSep 18, 2025
    risk 0.91cvss 10.0epss 1.00

    A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

  • CVE-2024-5276CriJun 25, 2024
    risk 0.74cvss 9.8epss 0.90

    A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not…

  • CVE-2024-0204CriJan 22, 2024
    risk 0.74cvss 9.8epss 0.95

    Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

  • CVE-2023-0669HigKEVFeb 6, 2023
    risk 0.69cvss 7.2epss 1.00

    Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

  • CVE-2024-25153CriMar 13, 2024
    risk 0.67cvss 9.8epss 0.42

    A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s…

  • CVE-2026-9862CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the…

  • CVE-2024-6633CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.01

    The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only…

  • CVE-2021-26837CriSep 19, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

  • CVE-2024-4332CriJun 3, 2024
    risk 0.61cvss epss 0.01

    An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is…

  • CVE-2023-2989CriJun 22, 2023
    risk 0.59cvss 9.1epss 0.01

    Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

  • CVE-2025-8450HigAug 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.

  • CVE-2024-5275HigJun 18, 2024
    risk 0.51cvss 7.8epss 0.00

    A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, for example, the private key for certificates. Exploit of this vulnerability could lead to a machine-in-the-middle (MiTM) attack…

  • CVE-2026-9863HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be…

  • CVE-2023-2990HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service

  • CVE-2025-14362HigApr 21, 2026
    risk 0.47cvss 7.3epss 0.00

    The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

  • CVE-2024-6632HigAug 27, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.

  • CVE-2024-0259HigMar 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a…

  • CVE-2024-25155HigMar 13, 2024
    risk 0.47cvss 7.2epss 0.00

    In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script…

  • CVE-2024-6769MedSep 26, 2024
    risk 0.44cvss 6.7epss 0.01

    A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process…

  • CVE-2026-1089MedApr 21, 2026
    risk 0.42cvss 6.5epss 0.00

    User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.