Skip to content
Noroxi

crushftp records

17 published records for vendor crushftp.

All records

17 records
  • Unauthenticated arbitrary file read and remote code execution in CrushFTP

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    crushftp · crushftpApr 22, 2024

  • CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    crushftp · crushftpApr 3, 2025

  • CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    crushftp · crushftpJul 18, 2025

  • CVE-2023-43177
    64This week

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

    CriticalCVSS 9.8WeaponizedEPSS 82%

    crushftp · crushftpNov 17, 2023

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 93%

    ssh · sshDec 18, 2023

  • CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

    CriticalCVSS 9.8No exploitEPSS 2%

    crushftp · crushftpAug 30, 2017

  • CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

    CriticalCVSS 9.8No exploitEPSS 1%

    crushftp · crushftpDec 9, 2024

  • CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files ac

    MediumCVSS 5.0No exploitEPSS 18%

    crushftp · crushftpApr 15, 2025

  • CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.

    MediumCVSS 6.1No exploitEPSS 1%

    crushftp · crushftpAug 30, 2017

  • CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    crushftp · crushftpAug 30, 2017

  • CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.

    MediumCVSS 6.1No exploitEPSS 1%

    crushftp · crushftpAug 30, 2017

  • CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.

    MediumCVSS 6.1No exploitEPSS 1%

    crushftp · crushftpDec 25, 2019

  • Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloa

    MediumCVSS 6.1No exploitEPSS 1%

    crushftp · crushftpMay 14, 2024

  • Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.

    MediumCVSS 6.1Proof of conceptEPSS 0%

    crushftp · crushftpNov 12, 2025

  • CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request

    MediumCVSS 5.0No exploitEPSS 9%

    crushftp · crushftpApr 15, 2025

  • An issue was discovered in CrushFTP 9.

    MediumCVSS 4.8No exploitEPSS 1%

    crushftp · crushftpSep 15, 2022

  • CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pe

    MediumCVSS 4.1Proof of conceptEPSS 0%

    crushftp · crushftpNov 7, 2025