CVE-2025-63420: CrushFTP

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

Affected products

  • CrushFTP CrushFTP: from 11.0.1, before 11.3.7_57 (fixed in 11.3.7_57)

Published 2025-11-07. Last modified 2026-06-17.