Medium severity4.8NVD Advisory· Published Mar 20, 2026· Updated Apr 10, 2026
CVE-2026-22895
CVE-2026-22895
Description
A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.qnap.com/en/security-advisory/qsa-26-15nvdVendor Advisory
News mentions
0No linked articles in our index yet.