CVE-2025-63420: CrushFTP
Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
Affected products
- CrushFTP CrushFTP: from 11.0.1, before 11.3.7_57 (fixed in 11.3.7_57)
Published 2025-11-07. Last modified 2026-06-17.