CVE-2026-22895

A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:*
cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:*
cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:*

History

10 Apr 2026, 20:51

Type Values Removed Values Added
References () https://www.qnap.com/en/security-advisory/qsa-26-15 - () https://www.qnap.com/en/security-advisory/qsa-26-15 - Vendor Advisory
CPE cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) ha sido reportada que afecta a QuFTP Service. Si un atacante remoto obtiene una cuenta de administrador, puede entonces explotar la vulnerabilidad para eludir mecanismos de seguridad o leer datos de la aplicación. Ya hemos corregido la vulnerabilidad en las siguientes versiones: QuFTP Service 1.4.3 y posteriores QuFTP Service 1.5.2 y posteriores QuFTP Service 1.6.2 y posteriores
First Time Qnap quftp
Qnap

20 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 17:16

Updated : 2026-04-10 20:51


NVD link : CVE-2026-22895

Mitre link : CVE-2026-22895

CVE.ORG link : CVE-2026-22895


JSON object : View

Products Affected

qnap

  • quftp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')