CVE-2025-63419
MEDIUMCrushFTP 11.3.6_48 - XSS
Title source: llmDescription
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.
Exploits (2)
Scores
CVSS v3
6.1
EPSS
0.0003
EPSS Percentile
7.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
crushftp/crushftp
< 11.3.7_60
Published
Nov 12, 2025
Tracked Since
Feb 18, 2026