CVE-2019-25046: Cerberusftp FTP Server

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

Affected products

  • Cerberusftp FTP Server: before 10.0.19 (fixed in 10.0.19); from 11.0.0, before 11.0.4 (fixed in 11.0.4)

Published 2021-06-10. Last modified 2026-06-17.