CVE-2025-47813: Wing FTP Server Information Disclosure Vulnerability

Medium severity, CVSS 4.3. Actively exploited: in CISA KEV since 2026-03-16. EPSS: 63.1% chance of exploitation in the next 30 days.

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Affected products

  • Wftpserver Wing FTP Server: before 7.4.4 (fixed in 7.4.4)

Published 2025-07-10. Last modified 2026-06-17.