Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

GoAnywhere MFT — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in GoAnywhere MFT, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration vulnerabilities associated with the Goanywhere Managed File Transfer product developed by HelpSystems. It aggregates security data to provide a comprehensive view of known flaws impacting this specific enterprise software solution. The content includes records of disclosed issues spanning from the initial release of the platform through recent updates, ensuring a broad historical context for security analysis. Readers can utilize this resource to track vendor security advisories, monitor the progression of identified weaknesses, and maintain situational awareness regarding the product's security posture. The collection is designed to help security professionals understand specific weakness classes, investigate the history of vulnerabilities linked to this product, and assess risk exposure over time. By centralizing these details, the page serves as a reference point for understanding how identified flaws have been addressed or remain relevant in current deployments. This approach supports informed decision-making for administrators and developers responsible for maintaining secure file transfer operations. The data reflects publicly available information compiled from various security feeds and vendor notifications. It aims to clarify the relationship between specific CWE categories and their manifestations within the Goanywhere ecosystem. Users seeking to audit their environment or prepare for compliance reviews can leverage this aggregated view to identify potential gaps in their defense strategies. The information is structured to facilitate quick lookup and comparative analysis across different versions and configurations.

Vendor: Fortra

CVE IDTitleCVSSSeverityPublished
CVE-2026-1089 User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups CWE-74 6.5 Medium2026-04-21
CVE-2026-0972 HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT CWE-74 5.4 Medium2026-04-21
CVE-2026-0971 GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout CWE-613 4.3 Medium2026-04-21
CVE-2025-14362 GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances CWE-307 7.3 High2026-04-21
CVE-2025-1241 Encryption vulnerable to brute-force decryption in GoAnywhere MFT CWE-326 5.8 Medium2026-04-21
CVE-2025-8148 CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT CWE-732 4.2 Medium2025-12-05
CVE-2025-10035 Deserialization Vulnerability in GoAnywhere MFT's License Servlet CWE-77 10.0 Critical2025-09-18
CVE-2025-3871 Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier CWE-862 5.3 Medium2025-07-16
CVE-2024-11922 Input Validation vulnerability in Web Client emails that do not go through Secure Mail CWE-79 6.3 Medium2025-04-28
CVE-2024-9945 Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0 CWE-200 5.3 Medium2024-12-13
CVE-2024-25157 Authentication bypass in GoAnywhere MFT prior to 7.6.0 CWE-303 6.5 Medium2024-08-14
CVE-2024-25156 Path traversal in GoAnywhere MFT 7.4.1 and Earlier CWE-22 6.5 Medium2024-03-14
CVE-2024-0204 Authentication Bypass in GoAnywhere MFT CWE-425 9.8 Critical2024-01-22
CVE-2023-0669 Fortra GoAnywhere MFT License Response Servlet Command Injection CWE-502 8.8 -2023-02-06

All 14 known CVE vulnerabilities affecting GoAnywhere MFT with full Chinese analysis, references, and POCs where available.