Description
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
Published: 2026-07-07
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated stored cross‑site scripting Upload File Shares API of LiquidFiles version 4.2.7. The flaw allows an attacker who has valid credentials to inject arbitrary JavaScript or HTML into the Name field, which is then rendered later in the user interface. When the stored name is displayed, the same privileges as the authenticated user.

Affected Systems

LiquidFiles version 4.2.7 is the only release known to contain the vulnerability. No other versions or product lines have been documented as affected.

Risk and Exploitability

Exploitation requires authentication and access to the Upload File Shares API. Once an attacker provides a malicious payload, it is stored and executed whenever the name is rendered, affecting only users who can see the value. The CVSS score of 5.4 indicates moderate severity, while the very low EPSS score (< 1 %) suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits at the time of reporting.

Generated by OpenCVE AI on July 26, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that removes the vulnerability from the Upload File Shares API.
  • Limit the use of the Upload File Shares API to privileged accounts and review permissions to ensure only authorizedImplement server‑side validation or output encoding on the Name field to prevent injection of executable code.
  • Enforce a strict Content Security Policy that blocks inline JavaScript to reduce the impact if the vulnerability remains.

Generated by OpenCVE AI on July 26, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via Name Parameter in Upload File Shares API

Wed, 22 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in LiquidFiles Upload File Shares API

Thu, 16 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in LiquidFiles Upload File Shares API

Wed, 15 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in LiquidFiles Upload File Shares API

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in LiquidFiles Upload File Shares API

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in Upload File Shares API – Arbitrary JavaScript Execution

Sat, 11 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS in Upload File Shares API – Arbitrary JavaScript Execution

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via Upload File Shares API in LiquidFiles v4.2.7

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via Upload File Shares API in LiquidFiles v4.2.7

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via Upload File Shares API in LiquidFiles 4.2.7

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via Upload File Shares API in LiquidFiles 4.2.7
Weaknesses CWE-79

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Liquidfiles
Liquidfiles liquidfiles
Vendors & Products Liquidfiles
Liquidfiles liquidfiles

Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
References

Subscriptions

Liquidfiles Liquidfiles
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T13:36:22.536Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36162

cve-icon Vulnrichment

Updated: 2026-07-08T13:35:44.131Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')