Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crushftp MEDIUM 6.1
CVE-2025-63419

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects …

Fix: 11.3.7_60+
Fix from $1,600 2025-11-12
Crushftp CRITICAL 9.8
CVE-2025-54309 KEVEPSS 94%

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote a…

Fix: 10.8.5 / 11.3.4_23+
Fix from $2,300 2025-07-18
Crushftp MEDIUM 5.0
CVE-2025-32102EPSS 8%

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /W…

Fix: after 11.3.1
Fix from $1,600 2025-04-15
Crushftp MEDIUM 5.0
CVE-2025-32103EPSS 17%

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible …

Fix: after 11.3.1
Fix from $1,600 2025-04-15
Crushftp CRITICAL 9.8
CVE-2025-31161 KEVEPSS 100%

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is us…

Fix: 10.8.4 / 11.3.1+
Fix from $2,300 2025-04-03
Crushftp CRITICAL 9.8
CVE-2024-53552

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

Fix: 10.8.3 / 11.2.3+
Fix from $2,300 2024-12-10
Crushftp MEDIUM 6.1
CVE-2024-22910

Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.

Fix: 10.6.1+
Fix from $1,600 2024-05-14
Crushftp CRITICAL 10.0
CVE-2024-4040 KEVEPSS 100%

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at…

Fix: 10.7.1 / 11.1.0+
Fix from $2,300 2024-04-22
Crushftp CRITICAL 9.8
CVE-2023-43177EPSS 82%

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

Fix: 10.5.2+
Fix from $2,300 2023-11-18
Crushftp MEDIUM 6.1
CVE-2018-18288

CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.

Fix: after 8.3.0
Fix from $1,600 2019-12-26
Crushftp CRITICAL 9.8
CVE-2017-14035

CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

No fix yet
Fix from $2,300 2017-08-30
Crushftp MEDIUM 6.1
CVE-2017-14036

CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.

Fix: after 7.7.0
Fix from $1,600 2017-08-30
Crushftp MEDIUM 6.1
CVE-2017-14037

CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.

Fix: after 7.7.0
Fix from $1,600 2017-08-30
Crushftp MEDIUM 6.1
CVE-2017-14038

CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.

Fix: after 7.7.0
Fix from $1,600 2017-08-30