CVE-2025-53897Medium· 6.8▾ SunlitKiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a spe…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in version 9.1.0.
kiteworks_managed_file_transfer < 9.1.0Upgrade past the affected range:
kiteworks_managed_file_transfer 9.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-53899High· 7.2Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53900Medium· 6.5Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53896High· 7.1Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2017-20120Medium· 4.3A vulnerability classified as problematic was found in TrueConf Server 4.3.7
CVE-2024-0830Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0
CVE-2025-5521Medium· 4.3A vulnerability was found in WuKongOpenSource WukongCRM 9.0