Progress Moveit Transfer vulnerabilities
38 known vulnerabilities affecting progress/moveit_transfer.
Total CVEs
38
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL13HIGH18MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2026-15967P3CRITICALCVSS 9.8fixed in 2025.1.5≥ 2026.0.0, < 2026.0.32026-07-23
CVE-2026-15967 [CRITICAL] CWE-613 CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEi
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd
CVE-2026-8650P3HIGHCVSS 7.5fixed in 2025.0.7≥ 2025.1.1, < 2025.1.3+1 more2026-07-08
CVE-2026-8650 [HIGH] CWE-23 CVE-2026-8650: Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This iss
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
nvd
CVE-2026-8651P3HIGHCVSS 7.5fixed in 2025.0.7≥ 2025.1.1, < 2025.1.3+1 more2026-07-08
CVE-2026-8651 [HIGH] CWE-290 CVE-2026-8651: Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module).
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
nvd
CVE-2020-8612P3CRITICALCVSS 9.0≥ 2019.2, < 2019.2.12020-02-14
CVE-2020-8612 [CRITICAL] CWE-79 CVE-2020-8612: In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint f
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
nvd
CVE-2025-11235P3HIGHCVSS 7.5≥ 2022.0.0, < 2022.0.10≥ 2022.1.0, < 2022.1.11+2 more2026-01-07
CVE-2025-11235 [HIGH] CWE-620 CVE-2025-11235: Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).T
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
nvd
CVE-2023-40043P3HIGHCVSS 7.2fixed in 2021.1.8≥ 2022.0.0, < 2022.0.8+2 more2023-09-20
CVE-2023-40043 [HIGH] CWE-89 CVE-2023-40043: In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system adminis
nvd
CVE-2026-10698P3HIGHCVSS 7.2≤ 2024.1.8≥ 2025.0.0, < 2025.0.8+3 more2026-07-08
CVE-2026-10698 [HIGH] CWE-943 CVE-2026-10698: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Tra
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
nvd
CVE-2025-10932P3HIGHCVSS 8.2≥ 2025.0.0, < 2025.0.3≥ 2024.1.0, < 2024.1.7+1 more2025-10-29
CVE-2025-10932 [HIGH] CWE-400 CVE-2025-10932: Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue
Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.3, from 2024.1.0 before 2024.1.7, from 2023.1.0 before 2023.1.16.
nvd
CVE-2026-10699P3HIGHCVSS 7.5≤ 2024.1.8≥ 2025.0.0, < 2025.0.8+3 more2026-07-08
CVE-2026-10699 [HIGH] CWE-401 CVE-2026-10699: Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom
Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
nvd
CVE-2023-6218P3HIGHCVSS 7.2≤ 2021.1.0≥ 2022.0.0, < 2022.0.9+3 more2023-11-29
CVE-2023-6218 [HIGH] CWE-269 CVE-2023-6218: In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.
nvd
CVE-2024-0396P3HIGHCVSS 7.1fixed in 2022.0.10≥ 2022.1.0, < 2022.1.11+2 more2024-01-17
CVE-2024-0396 [HIGH] CWE-20 CVE-2024-0396: In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in
nvd
CVE-2020-28647P4MEDIUMCVSS 5.4fixed in 2020.12020-11-17
CVE-2020-28647 [MEDIUM] CWE-79 CVE-2020-28647: In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within t
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
nvd
CVE-2025-13147P4MEDIUMCVSS 5.3fixed in 2024.1.8≥ 2025.0.0, < 2025.0.42025-11-19
CVE-2025-13147 [MEDIUM] CWE-918 CVE-2025-13147: Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVE
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
nvd
CVE-2023-42656P4MEDIUMCVSS 6.1fixed in 2021.1.8≥ 2022.0.0, < 2022.0.8+2 more2023-09-20
CVE-2023-42656 [MEDIUM] CWE-79 CVE-2023-42656: In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users during the package composition procedur
nvd
CVE-2023-6217P4MEDIUMCVSS 6.1≤ 2021.1.0≥ 2022.0.0, < 2022.0.9+3 more2023-11-29
CVE-2023-6217 [MEDIUM] CWE-79 CVE-2023-6217: In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer.
An attacker could craft a malicious payload targeting the system which comprises a MOVEit Gateway and MO
nvd
CVE-2026-11903P4MEDIUMCVSS 5.4≤ 2024.1.8≥ 2025.0.0, < 2025.0.8+3 more2026-07-08
CVE-2026-11903 [MEDIUM] CWE-79 CVE-2026-11903: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module).
This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
nvd
CVE-2026-15968P4MEDIUMCVSS 5.4fixed in 2025.1.5≥ 2026.0.0, < 2026.0.32026-07-23
CVE-2026-15968 [MEDIUM] CWE-79 CVE-2026-15968: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd
CVE-2024-2291P4MEDIUMCVSS 4.3fixed in 2022.0.11≥ 2022.1.0, < 2022.1.12+2 more2024-03-20
CVE-2024-2291 [MEDIUM] CWE-778 CVE-2024-2291: In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
nvd
← Previous2 / 2