Progress Moveit Transfer vulnerabilities
38 known vulnerabilities affecting progress/moveit_transfer.
Total CVEs
38
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL13HIGH18MEDIUM7
Vulnerabilities
Page 1 of 2
CVE-2023-34362P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 2021.0.7≥ 2021.1.0, < 2021.1.5+3 more2023-06-02
CVE-2023-34362 [CRITICAL] CWE-89 CVE-2023-34362: In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being us
nvd
CVE-2023-35708P1CRITICALCVSS 9.8ExploitedPoCRansomwarefixed in 2020.1.10≥ 2021.0.6, < 2021.0.8+4 more2023-06-16
CVE-2023-35708 [CRITICAL] CWE-89 CVE-2023-35708: In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submi
nvd
CVE-2023-36934P1CRITICALCVSS 9.1ExploitedPoCfixed in 12.1.11≥ 13.0.0, < 13.0.9+4 more2023-07-05
CVE-2023-36934 [CRITICAL] CWE-89 CVE-2023-36934: In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database.
nvd
CVE-2024-5806P1CRITICALCVSS 9.8ExploitedPoC≥ 2023.0.0, < 2023.0.11≥ 2023.1.0, < 2023.1.6+2 more2024-06-25
CVE-2024-5806 [CRITICAL] CWE-287 CVE-2024-5806: Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authenti
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
nvd
CVE-2023-35036P1CRITICALCVSS 9.1ExploitedRansomwarefixed in 2021.0.7≥ 2021.1.0, < 2021.1.5+3 more2023-06-12
CVE-2023-35036 [CRITICAL] CWE-89 CVE-2023-35036: In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a
nvd
CVE-2023-36932P2HIGHCVSS 8.1fixed in 2020.1.11≥ 2021.0, < 2021.0.9+4 more2023-07-05
CVE-2023-36932 [HIGH] CWE-89 CVE-2023-36932: In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer databa
nvd
CVE-2023-36933P3HIGHCVSS 7.5fixed in 2020.1.11≥ 2021.0, < 2021.0.9+4 more2023-07-05
CVE-2023-36933 [HIGH] CWE-755 CVE-2023-36933: In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
nvd
CVE-2021-38159P2CRITICALCVSS 9.8fixed in 2019.0.8≥ 2019.1, < 2019.1.7+4 more2021-08-07
CVE-2021-38159 [CRITICAL] CWE-89 CVE-2021-38159: In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVE
In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the
nvd
CVE-2026-8801P3CRITICALCVSS 9.8fixed in 2025.0.8≥ 2025.1.0, < 2025.1.42026-07-08
CVE-2026-8801 [CRITICAL] CWE-46 CVE-2026-8801: Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affec
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).
This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
nvd
CVE-2026-10697P3CRITICALCVSS 9.8fixed in 2025.1.5≥ 2026.0.0, < 2026.0.32026-07-23
CVE-2026-10697 [CRITICAL] CWE-287 CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transf
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd
CVE-2021-37614P3HIGHCVSS 8.8fixed in 2019.0.7≥ 2019.1, < 2019.1.6+4 more2021-08-05
CVE-2021-37614 [HIGH] CWE-89 CVE-2021-37614: In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVE
In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the struc
nvd
CVE-2021-31827P3HIGHCVSS 8.8fixed in 2021.02021-05-18
CVE-2021-31827 [HIGH] CWE-89 CVE-2021-31827: In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in th
In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer info
nvd
CVE-2023-42660P3HIGHCVSS 8.8fixed in 2021.1.8≥ 2022.0.0, < 2022.0.8+2 more2023-09-20
CVE-2023-42660 [HIGH] CWE-89 CVE-2023-42660: In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a craf
nvd
CVE-2026-8649P3CRITICALCVSS 9.8fixed in 2025.0.7≥ 2025.1.0, < 2025.1.32026-07-08
CVE-2026-8649 [CRITICAL] CWE-943 CVE-2026-8649: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Tra
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
nvd
CVE-2026-15966P3CRITICALCVSS 9.8fixed in 2025.1.5≥ 2026.0.0, < 2026.0.32026-07-23
CVE-2026-15966 [CRITICAL] CWE-942 CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Tran
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd
CVE-2020-8611P3HIGHCVSS 8.8≥ 2019.2, < 2019.2.12020-02-14
CVE-2020-8611 [HIGH] CWE-89 CVE-2020-8611: In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injectio
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL)
nvd
CVE-2021-33894P3HIGHCVSS 8.8fixed in 2019.0.6≥ 2019.1, < 2019.1.5+4 more2021-06-09
CVE-2021-33894 [HIGH] CWE-89 CVE-2021-33894: In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x be
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow a
nvd
CVE-2024-6576P3CRITICALCVSS 9.8≥ 2023.0.0, < 2023.0.12≥ 2023.1.0, < 2023.1.7+1 more2024-07-29
CVE-2024-6576 [CRITICAL] CWE-287 CVE-2024-6576: Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privileg
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.
nvd
CVE-2026-8800P3HIGHCVSS 8.8fixed in 2025.0.7≥ 2025.1.1, < 2025.1.3+1 more2026-07-08
CVE-2026-8800 [HIGH] CWE-863 CVE-2026-8800: Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue a
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
nvd
CVE-2025-2324P3HIGHCVSS 8.8≥ 2023.1.0, < 2023.1.12≥ 2024.0.0, < 2024.0.8+1 more2025-03-19
CVE-2025-2324 [HIGH] CWE-269 CVE-2025-2324: Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVE
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.
nvd
1 / 2Next →