📦 Crushftp

by Crushftp

🔍 What is Crushftp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54309

CRITICAL CVSS 9.0 Jul 18, 2025

This vulnerability in CrushFTP allows remote attackers to bypass AS2 validation and gain administrative access via HTTPS when the DMZ proxy feature is not used. It affects CrushFTP servers running vul...

CVE-2025-31161

CRITICAL CVSS 9.8 Apr 3, 2025

This critical authentication bypass vulnerability in CrushFTP allows unauthenticated attackers to gain administrative access by exploiting a race condition and header manipulation in the AWS4-HMAC aut...

CVE-2024-53552

CRITICAL CVSS 9.8 Dec 10, 2024

This vulnerability in CrushFTP allows attackers to bypass password reset mechanisms, potentially leading to complete account takeover. It affects CrushFTP 10 versions before 10.8.3 and CrushFTP 11 ver...

CVE-2024-4040

CRITICAL CVSS 9.8 Apr 22, 2024

CVE-2024-4040 is a critical server-side template injection vulnerability in CrushFTP that allows unauthenticated attackers to read files outside the sandbox, bypass authentication to gain admin access...

CVE-2025-63419

MEDIUM CVSS 6.1 Nov 12, 2025

This CVE describes a Cross-Site Scripting (XSS) vulnerability in CrushFTP's file sharing feature where malicious filenames are reflected in email bodies without proper sanitization. Attackers can inje...

CVE-2025-63420

MEDIUM CVSS 4.1 Nov 7, 2025

CVE-2025-63420 is a stored HTML injection vulnerability in CrushFTP11's admin panel that allows attackers to inject malicious HTML into the 'Who Created Folder' report. This enables persistent HTML ex...

CVE-2025-32103

MEDIUM CVSS 5.0 Apr 15, 2025

CVE-2025-32103 is a directory traversal vulnerability in CrushFTP that allows attackers to bypass SecurityManager restrictions and read files accessible via SMB UNC share paths. This affects CrushFTP ...