Known vulnerabilities in CrushFTP CrushFTP
11.4.0
11.3.7
11.3.6
11.3.5
11.3.4
10.8.5
8.1.0
8.0.4
8.0.3
8.0.2
8.3.2
8.3.1
9.4.0
9.3.2
9.3.0
9.2.0
9.1.0
9.0.0
11.3.3
11.3.2
11.3.0
11.2.2
11.2.0
11.0.1
10.8.1
10.8.0
10.7.1
10.6.1
10.5.6
10.5.5
10.5.4
10.5.3
10.5.1
10.5.0
10.4.0
10.3.0
10.2.0
10.1.0
10.0.0
10.8.4
11.3.1
11.2.3
10.8.3
11.2.1
10.8.2
11.1.0
Security bulletins (13)
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2025120138: Multiple vulnerabilities in CrushFTP | Medium | 01.12.2025 | |
| SB2025072108: Authentication bypass in CrushFTP | Critical | 21.07.2025 | |
| SB2025061359: Cross-site scripting in CrushFTP | Low | 13.06.2025 | |
| SB2025032652: Missing authorization in CrushFTP | Critical | 26.03.2025 | |
| SB2025032651: Account takeover via password reset feature in CrushFTP | Medium | 26.03.2025 | |
| SB2025032650: Cross-site scripting in CrushFTP | Low | 26.03.2025 | |
| SB2024112179: Cross-site scripting in CrushFTP | Medium | 21.11.2024 | |
| SB2024042213: Arbitrary file download in CrushFTP | High | 22.04.2024 | |
| SB2019122649: Open redirect in CrushFTP | Low | 26.12.2019 | |
| SB2017090203: CRLF injection in CrushFTP | Medium | 02.09.2017 | |
| SB2017090118: Deserialization of Untrusted Data in CrushFTP | High | 01.09.2017 | |
| SB2017090119: Cross-site scripting in CrushFTP | Low | 01.09.2017 | |
| SB2017090120: Open redirect in CrushFTP | Low | 01.09.2017 |