CVE-2025-63420

MEDIUM

CrushFTP11 <11.3.7_57 - XSS

Title source: llm

Description

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

Exploits (2)

nomisec WRITEUP 2 stars
by MMAKINGDOM · poc
https://github.com/MMAKINGDOM/CVE-2025-63420
nomisec WRITEUP
by hossainshadat · poc
https://github.com/hossainshadat/CVE-2025-63420

Scores

CVSS v3 4.1
EPSS 0.0003
EPSS Percentile 8.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
crushftp/crushftp 11.0.1 - 11.3.7_57
Published Nov 07, 2025
Tracked Since Feb 18, 2026