CVE-2025-47813: Wing FTP Server Information Disclosure Vulnerability
Medium severity, CVSS 4.3. Actively exploited: in CISA KEV since 2026-03-16. EPSS: 63.1% chance of exploitation in the next 30 days.
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Affected products
- Wftpserver Wing FTP Server: before 7.4.4 (fixed in 7.4.4)
Published 2025-07-10. Last modified 2026-06-17.