📦 Goanywhere Managed File Transfer

by Fortra

🔍 What is Goanywhere Managed File Transfer?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10035

CRITICAL CVSS 10.0 Sep 18, 2025

A critical deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet allows attackers with forged license signatures to execute arbitrary commands through object deserialization. This a...

CVE-2024-0204

CRITICAL CVSS 9.8 Jan 22, 2024

This vulnerability allows an unauthenticated attacker to bypass authentication in Fortra's GoAnywhere MFT and create an administrative user via the administration portal. This affects all GoAnywhere M...

CVE-2023-0669

HIGH CVSS 7.2 Feb 6, 2023

CVE-2023-0669 is a pre-authentication remote code execution vulnerability in Fortra GoAnywhere MFT that allows unauthenticated attackers to execute arbitrary commands on affected systems by exploiting...

CVE-2025-8148

MEDIUM CVSS 4.2 Dec 5, 2025

This vulnerability allows Web Users in Fortra's GoAnywhere MFT who are configured for password-only SFTP authentication to bypass this restriction and log in using SSH keys. This affects organizations...

CVE-2024-11922

MEDIUM CVSS 6.3 Apr 28, 2025

This cross-site scripting (XSS) vulnerability in Fortra's GoAnywhere web client allows authenticated attackers with email triggering permissions to inject malicious HTML or JavaScript into emails. The...

CVE-2024-25157

MEDIUM CVSS 6.5 Aug 14, 2024

This authentication bypass vulnerability in GoAnywhere MFT allows Admin Users with Agent Console access to circumvent permission checks and access unauthorized pages. This could lead to unauthorized i...