CVE-2025-47813: listed in the CISA KEV catalog
CVE-2025-47813 · CVSS 4.3 MEDIUM · EPSS 60% · KEV 2026-03-16
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Is CVE-2025-47813 exploited?
- Listed in the CISA KEV catalog on 2026-03-16.
- Federal remediation due 2026-03-30.
- Past that date by 138 days.
- EPSS puts exploitation in the next 30 days at 60%.
- Public exploit code: none found in monitored sources.
- Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-47813
Primary sources
What this record does not say
- No affected package data.
- No patch identifier.
KEV and EPSS are re-checked daily. Record last updated 2026-08-11.