Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2025-27889

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

  • Published: Jul 10, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-27889
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.4
  • AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

CWEs: