Where
-Infinity
0

Vendor Risk Score

See how crushftp compares to other vendors in security performance

View Risk Score →

Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state

First published (updated )
Social
reddit

Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state

First published (updated )
Social
reddit

CrushFTP CrushFTPXSS

Risk 38
Severity
6.1
First published (updated )

CrushFTP CrushFTPXSS

Risk 21
Severity
4.1
First published (updated )

The One Where We Just Steal The Vulnerabilities (CrushFTP CVE-2025-54309) - watchTowr Labs

First published (updated )
Social
reddit
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

New Critical CrushFTP CVE-2025-54309 RCE Explained + PoC

First published (updated )
Social
reddit

BleepingComputerOver 1,000 CrushFTP servers exposed to ongoing hijack attacks

First published (updated )

BleepingComputerCrushFTP zero-day exploited to gain admin access on servers

First published (updated )

BleepingComputerCrushFTP zero-day exploited in attacks to gain admin access on servers

First published (updated )

BleepingComputerNew CrushFTP zero-day exploited in attacks to hijack servers

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerNew CrushFTP zero-day exploited in attacks to hijack servers

First published (updated )

CrushFTP CrushFTPCrushFTP Unprotected Alternate Channel Vulnerability

Risk 99
Severity
9.8
First published (updated )

CVE-2025-31161 is being actively exploited and it's not getting the attention it should.

First published (updated )
Social
reddit

CrushFTP CrushftpPath Traversal

Risk 18
Severity
5
EPSS
0.07%
First published (updated )

CrushFTP CrushftpSSRF

Risk 18
Severity
5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dark ReadingDisclosure Drama Clouds CrushFTP Vulnerability Exploitation

First published (updated )

CrushFTP CrushftpCrushFTP Authentication Bypass Vulnerability

Risk 92
Severity
9.8
EPSS
38.42%
First published (updated )

CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog

First published (updated )
Social
reddit

The RegisterCrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug

First published (updated )

CrushFTP CrushftpCrushFTP HTTP Unauthenticated Access

Risk 65
Severity
9
EPSS
17.54%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerCrushFTP warns users to patch unauthenticated access flaw immediately

First published (updated )

CrushFTP CrushftpStored XSS in CrushFTP

Risk 80
Severity
9.6
First published (updated )

CrushFTP CrushFTPCrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeove…

Risk 86
Severity
9.8
First published (updated )

CrushFTP CrushftpXSS

Risk 38
Severity
6.1
First published (updated )

CrushFTP CrushftpUnauthenticated arbitrary file read and remote code execution in CrushFTP

Risk 100
Severity
10
EPSS
96.61%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerCrushFTP warns users to patch exploited zero-day “immediately”

First published (updated )

BleepingComputerCrushFTP warns users to patch exploited zero-day “immediately”

First published (updated )

Fortinet FortiSIEMOpenSSH Terrapin attack (CVE-2023-48795)

Risk 37
Severity
6
First published (updated )

BleepingComputerExploit for CrushFTP RCE chain released, patch now

First published (updated )

CrushFTP CrushftpCrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determin…

Risk 99
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203