GO-2022-0964: SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo
GO-2022-1015: SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo
GO-2024-2940: SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo
GO-2024-3283: SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo
GO-2024-3300: sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo
GO-2025-3458: SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo