VulnSea

proftpd has 3 CVEs on record between 2025 and 2026. The median CVSS is 8.1 (high), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
0 prev 2

Products

  • proftpd 3
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

proftpd vulnerabilities

CVEs affecting proftpd, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-35025High· 8.1
3mo ago

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attack…

Twilightproftpd · proftpdEPSS 0.35%via NVD
CVE-2026-42167High· 8.1PoC
4mo ago

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

Midnightproftpd · proftpdEPSS 7.4%via NVD
CVE-2010-20103Critical· 9.8PoC
1y ago

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…

Abyssalproftpd · proftpdEPSS 5.1%via NVD
proftpd vulnerabilities (CVEs) · VulnSea