CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
https://github.com/MMAKINGDOM/CVE-2025-63420/
https://gist.github.com/MMAKINGDOM/791d264c27656f0a4aa3c0ae35075e70