vciy

CVEs we hold for Fortra

Records whose assigning authority named Fortra as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9863Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerabilityFortra Core Privileged Access Manager (BoKS)
CVE-2026-9862Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityFortra Core Privileged Access Manager (BoKS)
CVE-2026-15913Path Traversal in Fortra's GoAnywhere MFT EndpointFortra GoAnywhere MFT
CVE-2026-12164Privilege Escalation in Fortra File Integrity Monitoring (FIM)Fortra File Integrity Monitoring (FIM)
CVE-2026-12163Stored XSS in Fortra File Integrity Monitoring (FIM)Fortra File Integrity Monitoring (FIM)
CVE-2026-1089User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS LookupsFortra GoAnywhere MFT
CVE-2026-0972HTML Injection possible in system generated emails in Fortra's GoAnywhere MFTFortra GoAnywhere MFT
CVE-2026-0971GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeoutFortra GoAnywhere MFT
CVE-2025-8450Unrestricted File Upload in FileCatalystFortra FileCatalyst
CVE-2025-8148CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFTFortra GoAnywhere MFT
CVE-2025-5141Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the CacheFortra Core Privileged Access Manager (BoKS)
CVE-2025-3871Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierFortra GoAnywhere MFT
CVE-2025-14362GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain CircumstancesFortra GoAnywhere MFT
CVE-2025-13532Weak Password Hash in Core Privileged Access Manager (BoKS)Fortra Core Privileged Access Manager (BoKS)
CVE-2025-1241Encryption vulnerable to brute-force decryption in GoAnywhere MFTFortra GoAnywhere MFT
CVE-2025-10035Deserialization Vulnerability in GoAnywhere MFT's License ServletFortra GoAnywhere MFT
CVE-2025-0049Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0Fortra GoAnywhere
CVE-2024-9945Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0Fortra GoAnywhere MFT
CVE-2024-8264Sensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterprise prior to…Fortra Robot Schedule Enterprise
CVE-2024-6633Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-6632SQL Injection in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-5276SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)Fortra FileCatalyst Workflow
CVE-2024-5275Hard-coded password in FileCatalyst Direct 3.8.10 Build 138 TransferAgent (and earlier) and FileCatalyst Workflow 5.1.6…Fortra FileCatalyst Workflow
CVE-2024-4332Improper Authentication in Tripwire Enterprise 9.1.0 APIsFortra Tripwire Enterprise
CVE-2024-3334USB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0Fortra Digital Guardian Agent
CVE-2024-25157Authentication bypass in GoAnywhere MFT prior to 7.6.0Fortra GoAnywhere MFT
CVE-2024-25156Path traversal in GoAnywhere MFT 7.4.1 and EarlierFortra GoAnywhere MFT
CVE-2024-25155Reflected Cross-Site Scripting (XSS) in FileCatalyst Direct 3.8.8 and earlierFortra FileCatalyst
CVE-2024-25154Path Traversal in FileCatalyst Direct 3.8.8 and EarlierFortra FileCatalyst
CVE-2024-25153Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114Fortra FileCatalyst
CVE-2024-11923Sensitive Information Disclosure in Fortra Application Hub Prior to version 1.3Fortra Application Hub
CVE-2024-11922Input Validation vulnerability in Web Client emails that do not go through Secure MailFortra GoAnywhere MFT
CVE-2024-0259Privilege Escalation in Robot Schedule Enterprise Agent for Windows prior to version 3.04Fortra Robot Schedule Enterprise Agent
CVE-2024-0204Authentication Bypass in GoAnywhere MFTFortra GoAnywhere MFT
CVE-2023-6253Saved Uninstall Key in Digital Guardian Agent UninstallerFortra Digital Guardian Agent
CVE-2023-2991Fortra Globalscape Administration Server Information DisclosureFortra Globalscape EFT
CVE-2023-2990Fortra Globalscape Administration Server Denial of ServiceFortra Globalscape EFT
CVE-2023-2989Fortra Globalscape Administration Server Out of Bounds Memory ReadFortra Globalscape EFT
CVE-2023-0669Fortra GoAnywhere MFT License Response Servlet Command InjectionFortra Goanywhere MFT

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.