- How many CVEs does Fortra have?
- Fortra has 40 published CVE records since 2021, including 18 in the last two years.
- How many Fortra CVEs are in CISA KEV?
- Yes — 2 of Fortra's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which Fortra products have the most CVEs?
- The Fortra products with the most published CVEs are Goanywhere MFT, goanywhere_managed_file_transfer, FileCatalyst Workflow, FileCatalyst, Core Privileged Access Manager (BoKS).
- What are the most common weakness types in Fortra CVEs?
- Fortra's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- Are there public exploits for Fortra vulnerabilities?
- Yes — 10 of Fortra's CVEs have a known public exploit.
- How many critical Fortra vulnerabilities are there?
- Fortra has 11 critical and 8 high-severity CVEs.
- What is the average severity of Fortra CVEs?
- The average CVSS base score across Fortra's scored CVEs is 7.0.