Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Goanywhere MFT — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Goanywhere MFT, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with Goanywhere MFT, specifically focusing on weaknesses documented in the Common Weakness Enumeration (CWE) framework. It collects a comprehensive list of reported flaws, including critical severity issues, medium-risk configuration errors, and low-impact informational findings affecting various versions of the Goanywhere Managed File Transfer software. The data covers vulnerability disclosures and advisories released from early 2018 through the present day, ensuring that users have access to both historical context and recently identified threats. By navigating this resource, security professionals and system administrators can efficiently track the progression of advisories issued by the vendor over time. Users can also gain a deeper understanding of specific weakness classes, such as SQL injection or path traversal, as they apply to this particular file transfer platform. Furthermore, the page allows for a detailed lookup of a product's vulnerability history, enabling teams to assess the security posture of their deployed instances and prioritize patching efforts based on established trends. This centralized view helps organizations mitigate risks by providing clear insights into the frequency and nature of defects found in the software, supporting more informed decision-making for compliance and operational continuity without requiring direct vendor support tickets for basic historical data.

Vendor: Fortra

CVE IDTitleCVSSSeverityPublished
CVE-2026-1089 User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups CWE-74 6.5 Medium2026-04-21
CVE-2026-0972 HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT CWE-74 5.4 Medium2026-04-21
CVE-2026-0971 GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout CWE-613 4.3 Medium2026-04-21
CVE-2025-14362 GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances CWE-307 7.3 High2026-04-21
CVE-2025-1241 Encryption vulnerable to brute-force decryption in GoAnywhere MFT CWE-326 5.8 Medium2026-04-21
CVE-2025-8148 CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT CWE-732 4.2 Medium2025-12-05
CVE-2025-10035 Deserialization Vulnerability in GoAnywhere MFT's License Servlet CWE-77 10.0 Critical2025-09-18
CVE-2025-3871 Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier CWE-862 5.3 Medium2025-07-16
CVE-2024-11922 Input Validation vulnerability in Web Client emails that do not go through Secure Mail CWE-79 6.3 Medium2025-04-28
CVE-2024-9945 Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0 CWE-200 5.3 Medium2024-12-13
CVE-2024-25157 Authentication bypass in GoAnywhere MFT prior to 7.6.0 CWE-303 6.5 Medium2024-08-14
CVE-2024-25156 Path traversal in GoAnywhere MFT 7.4.1 and Earlier CWE-22 6.5 Medium2024-03-14
CVE-2024-0204 Authentication Bypass in GoAnywhere MFT CWE-425 9.8 Critical2024-01-22
CVE-2023-0669 Fortra GoAnywhere MFT License Response Servlet Command Injection CWE-502 8.8 -2023-02-06

All 14 known CVE vulnerabilities affecting Goanywhere MFT with full Chinese analysis, references, and POCs where available.