We have already fixed the vulnerability in the following versions:
QuFTP Service 1.4.3 and later
QuFTP Service 1.5.2 and later
QuFTP Service 1.6.2 and later
Project Subscriptions
No advisories yet.
Solution
We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-15 |
|
Fri, 10 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap quftp |
|
| CPEs | cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap quftp |
|
| Metrics |
cvssV3_1
|
Fri, 27 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems quftp Service |
|
| Vendors & Products |
Qnap Systems
Qnap Systems quftp Service |
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later | |
| Title | QuFTP Service | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-03-25T14:03:29.588Z
Reserved: 2026-01-13T07:49:08.783Z
Link: CVE-2026-22895
Updated: 2026-03-25T14:03:26.323Z
Status : Analyzed
Published: 2026-03-20T17:16:43.980
Modified: 2026-04-10T20:51:58.103
Link: CVE-2026-22895
No data.
OpenCVE Enrichment
Updated: 2026-04-13T14:28:25Z