crushftp records
17 published records for vendor crushftp.
Researcher profile
- Entered KEV
- 3 · 17.6%
- Weaponized
- 4 · 23.5%
- Pre-auth RCE
- 2
- With a fix record
- 11.8%
- Median publish → KEV
- 4 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-40 Path Traversal: '\\UNC\share\name\' (Windows UNC Share)1
- CWE-420 Unprotected Alternate Channel1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2024-4040Weaponized | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Critical10.0 | KEV | 99.5% | Apr 22, 2024 |
99Now | CVE-2025-31161Weaponized | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instacrushftp · crushftp · CWE-305 | Critical9.8 | KEV | 100.0% | Apr 3, 2025 |
97Now | CVE-2025-54309Weaponized | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Critical9.8 | KEV | 94.9% | Jul 18, 2025 |
64This week | CVE-2023-43177Weaponized | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.crushftp · crushftp · CWE-913 | Critical9.8 | — | 81.8% | Nov 17, 2023 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.3% | Dec 18, 2023 |
39Monitor | CVE-2017-14035No exploit | CrushFTP 8.x before 8.2.0 has a serialization vulnerability.crushftp · crushftp · CWE-502 | Critical9.8 | — | 1.6% | Aug 30, 2017 |
39Monitor | CVE-2024-53552No exploit | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.crushftp · crushftp · CWE-640 | Critical9.8 | — | 0.8% | Dec 9, 2024 |
25Monitor | CVE-2025-32103No exploit | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accrushftp · crushftp · CWE-40 | Medium5.0 | — | 18.1% | Apr 15, 2025 |
24Monitor | CVE-2017-14038No exploit | CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.crushftp · crushftp · CWE-601 | Medium6.1 | — | 0.7% | Aug 30, 2017 |
24Monitor | CVE-2017-14036No exploit | CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.crushftp · crushftp · CWE-79 | Medium6.1 | — | 0.7% | Aug 30, 2017 |
24Monitor | CVE-2017-14037No exploit | CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.crushftp · crushftp · CWE-93 | Medium6.1 | — | 0.7% | Aug 30, 2017 |
24Monitor | CVE-2018-18288No exploit | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.crushftp · crushftp · CWE-601 | Medium6.1 | — | 0.6% | Dec 25, 2019 |
24Monitor | CVE-2024-22910No exploit | Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloacrushftp · crushftp · CWE-79 | Medium6.1 | — | 0.5% | May 14, 2024 |
24Monitor | CVE-2025-63419Proof of concept | Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.crushftp · crushftp · CWE-79 | Medium6.1 | — | 0.2% | Nov 12, 2025 |
23Monitor | CVE-2025-32102No exploit | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request crushftp · crushftp · CWE-918 | Medium5.0 | — | 9.4% | Apr 15, 2025 |
19Monitor | CVE-2021-44076No exploit | An issue was discovered in CrushFTP 9.crushftp · crushftp · CWE-79 | Medium4.8 | — | 0.7% | Sep 15, 2022 |
16Monitor | CVE-2025-63420Proof of concept | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pecrushftp · crushftp · CWE-79 | Medium4.1 | — | 0.3% | Nov 7, 2025 |
- CVE-2024-4040100Now
Unauthenticated arbitrary file read and remote code execution in CrushFTP
CriticalCVSS 10.0KEVWeaponizedEPSS 100%crushftp · crushftpApr 22, 2024
- CVE-2025-3116199Now
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta
CriticalCVSS 9.8KEVWeaponizedEPSS 100%crushftp · crushftpApr 3, 2025
- CVE-2025-5430997Now
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
CriticalCVSS 9.8KEVWeaponizedEPSS 95%crushftp · crushftpJul 18, 2025
- CVE-2023-4317764This week
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
CriticalCVSS 9.8WeaponizedEPSS 82%crushftp · crushftpNov 17, 2023
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 93%ssh · sshDec 18, 2023
- CVE-2017-1403539Monitor
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%crushftp · crushftpAug 30, 2017
- CVE-2024-5355239Monitor
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
CriticalCVSS 9.8No exploitEPSS 1%crushftp · crushftpDec 9, 2024
- CVE-2025-3210325Monitor
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files ac
MediumCVSS 5.0No exploitEPSS 18%crushftp · crushftpApr 15, 2025
- CVE-2017-1403824Monitor
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
MediumCVSS 6.1No exploitEPSS 1%crushftp · crushftpAug 30, 2017
- CVE-2017-1403624Monitor
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
MediumCVSS 6.1No exploitEPSS 1%crushftp · crushftpAug 30, 2017
- CVE-2017-1403724Monitor
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
MediumCVSS 6.1No exploitEPSS 1%crushftp · crushftpAug 30, 2017
- CVE-2018-1828824Monitor
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
MediumCVSS 6.1No exploitEPSS 1%crushftp · crushftpDec 25, 2019
- CVE-2024-2291024Monitor
Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloa
MediumCVSS 6.1No exploitEPSS 1%crushftp · crushftpMay 14, 2024
- CVE-2025-6341924Monitor
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.
MediumCVSS 6.1Proof of conceptEPSS 0%crushftp · crushftpNov 12, 2025
- CVE-2025-3210223Monitor
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request
MediumCVSS 5.0No exploitEPSS 9%crushftp · crushftpApr 15, 2025
- CVE-2021-4407619Monitor
An issue was discovered in CrushFTP 9.
MediumCVSS 4.8No exploitEPSS 1%crushftp · crushftpSep 15, 2022
- CVE-2025-6342016Monitor
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pe
MediumCVSS 4.1Proof of conceptEPSS 0%crushftp · crushftpNov 7, 2025