Home/Product/crushftp
Product

crushftp

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-63419
< 11.3.7_60
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, th
6.1MEDIUM
CVE-2025-63420
>= 11.0.1 and < 11.3.7_57
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), e
4.1MEDIUM
CVE-2025-54309
>= 10.0.0 and < 10.8.5
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequen
9.0CRITICAL
CVE-2025-32103
>= 9.0.0 and <= 11.3.1
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to rea
5.0MEDIUM
CVE-2025-32102
>= 9.0.0 and <= 11.3.1
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocke
5.0MEDIUM
CVE-2025-31161
>= 10.0.0 and < 10.8.4
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ p
9.8CRITICAL
CVE-2024-53552
>= 10.0.0 and < 10.8.3
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
9.8CRITICAL
CVE-2024-22910
< 10.6.1
Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a craf
6.1MEDIUM
CVE-2024-4040
>= 10.0.0 and < 10.7.1
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauth
9.8CRITICAL
CVE-2023-48795
<= 10.6.0
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9MEDIUM
CVE-2023-43177
< 10.5.2
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
9.8CRITICAL
CVE-2021-44076
>= 9.0.0 and < 9.4.0_15
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attac
4.8MEDIUM
CVE-2018-18288
<= 8.3.0
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
6.1MEDIUM
CVE-2017-14038
<= 7.7.0
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
6.1MEDIUM
CVE-2017-14037
<= 7.7.0
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
6.1MEDIUM
CVE-2017-14036
<= 7.7.0
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
6.1MEDIUM
CVE-2017-14035
all versions
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin