CVE-2016-10732: ProjectSend

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.

Affected products

Published 2018-10-29. Last modified 2026-06-17.