QNAP QuFTP Service Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability exists in QuFTP Service versions 1.4.x, 1.5.x, and 1.6.x. This vulnerability allows remote attackers with administrator accounts to exploit the issue, potentially bypassing security mechanisms or accessing application data.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Remediation

Users are advised to update QuFTP Service to the latest version. Instructions for updating can be found in the QNAP App Center.

Added: Mar 20, 2026, 5:21 PM
Updated: Mar 20, 2026, 5:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
4.8
remediation
0.0
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.