CrushFTP is a file-transfer server product that, despite a narrow product portfolio, ranks among the more prominent vendors in the vulnerability landscape and presents a focused but critical attack surface for organizations deploying it. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have an elevated tendency toward confirmed in-the-wild exploitation, and frequently acquire public exploit code; the recurring weakness classes—including cross-site scripting, open redirects, authentication bypass, unsafe deserialization, and improper code-resource management—reflect the web-accessible and dynamic-code demands of an FTP-server platform. Defenders should treat CrushFTP advisories as high-priority and prioritize patching, particularly for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crushftp over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31161CRITICAL CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild i | Apr 3, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-4040CRITICAL A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the | Apr 22, 2024 | 10.0 | 98 | YES | YES |
CVE-2025-54309CRITICAL CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access | Jul 18, 2025 | 9.8 | 97 | YES | YES |
CVE-2023-43177CRITICAL CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | Nov 18, 2023 | 9.8 | 88 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2017-14035CRITICAL CrushFTP 8.x before 8.2.0 has a serialization vulnerability. | Aug 30, 2017 | 9.8 | 30 | NO | NO |
CVE-2024-53552CRITICAL CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover. | Dec 10, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-32103MEDIUM CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, | Apr 15, 2025 | 5.0 | 25 | NO | NO |
CVE-2025-32102MEDIUM CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI. | Apr 15, 2025 | 5.0 | 22 | NO | NO |
CVE-2018-18288MEDIUM CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection. | Dec 26, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crushftp.
Media articles that mention a CVE ID that affects a product developed by Crushftp — matched by CVE ID, not by vendor name.