github.com/drakkan/sftpgo
Full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob
Activity
- Latest release
- 5y ago
- Total releases
- 6
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- 12.4k
Details
- First release
- Jul 06, 2020
| Version | Released | |
|---|---|---|
v1.2.2
patch
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (34)
+ 26 more |
|
v1.2.1
patch
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (34)
+ 26 more |
|
v1.2.0
minor
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (34)
+ 26 more |
|
v1.1.1
patch
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (33)
+ 25 more |
|
v1.1.0
minor
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (33)
+ 25 more |
|
v1.0.0
initial
10 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GO-2024-3283
GHSA-49cc-xrjf-9qf7
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
initial
Dependencies (26)
+ 18 more |