CrushFTP是CrushFTP公司的一款文件传输服务器。 CrushFTP 11.3.7_50版本存在安全漏洞,该漏洞源于Admin Panel中Reports/Who Created Folder功能未正确处理输入,可能导致存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions. | https://github.com/MMAKINGDOM/CVE-2025-63420 | POC Details |
| 2 | None | https://github.com/hossainshadat/CVE-2025-63420 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-12875 | 5.3 MEDIUM | mruby array.c ary_fill_exec out-of-bounds write |
| CVE-2025-12861 | 4.7 MEDIUM | DedeBIZ spec_add.php sql injection |
| CVE-2025-12860 | 4.7 MEDIUM | DedeBIZ freelist_main.php sql injection |
| CVE-2025-12859 | 4.7 MEDIUM | DedeBIZ templets_one_edit.php sql injection |
| CVE-2025-12854 | 3.7 LOW | newbee-mall-plus seckillExecution executeSeckill authorization |
| CVE-2025-63689 | money-pos 安全漏洞 | |
| CVE-2025-61261 | CKEditor 安全漏洞 | |
| CVE-2025-63686 | PersonManage 安全漏洞 | |
| CVE-2025-63784 | Onlook 安全漏洞 | |
| CVE-2025-63717 | SourceCodester Pet Grooming Management Software 安全漏洞 | |
| CVE-2025-63640 | Sourcecodester Medicine Reminder App 安全漏洞 | |
| CVE-2025-63690 | pig 安全漏洞 | |
| CVE-2025-63785 | Onlook 安全漏洞 | |
| CVE-2025-63687 | forest 安全漏洞 | |
| CVE-2025-60574 | tQuadra CMS 安全漏洞 | |
| CVE-2025-63543 | TechStore Pro 安全漏洞 | |
| CVE-2025-63691 | pig 安全漏洞 | |
| CVE-2025-63718 | SourceCodester PQMS 安全漏洞 | |
| CVE-2025-63714 | SourceCodester User Account Generator 安全漏洞 | |
| CVE-2025-63544 | TechStore Pro 安全漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet