CVE-2025-63419

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/11/2025
Last modified:
31/12/2025

Description

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* 11.3.7_60 (excluding)