We have already fixed the vulnerability in the following versions:
QuFTP Service 1.4.3 and later
QuFTP Service 1.5.2 and later
QuFTP Service 1.6.2 and later
Project Subscriptions
No advisories yet.
Solution
We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-15 |
|
Tue, 09 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 10 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap quftp |
|
| CPEs | cpe:2.3:a:qnap:quftp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap quftp |
|
| Metrics |
cvssV3_1
|
Fri, 27 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems quftp Service |
|
| Vendors & Products |
Qnap Systems
Qnap Systems quftp Service |
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later | |
| Title | QuFTP Service | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-06-09T04:12:16.251Z
Reserved: 2026-01-13T07:49:08.783Z
Link: CVE-2026-22895
Updated: 2026-03-25T14:03:26.323Z
Status : Modified
Published: 2026-03-20T17:16:43.980
Modified: 2026-06-09T05:16:34.237
Link: CVE-2026-22895
No data.
OpenCVE Enrichment
Updated: 2026-06-09T06:00:15Z