Description
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.
Published: 2026-07-07
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An HTML injection flaw in LiquidFiles 4.2.7 allows authenticated users to upload a crafted HTML file. When a victim later accesses the file in a browser, the injected script executes in the victim’s browser context, enabling arbitrary JavaScript execution. This stored XSS vulnerability can be used to steal session cookies, manipulate the user interface, and perform actions within the user’s session.

Affected Systems

LiquidFiles 4.2.7 is affected. No other product versions are mentioned.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation. Exploitation requires an attacker to first obtain valid credentials to upload a malicious file and then rely on a second authorized user to open the file in a browser, thereby decreasing the immediate risk relative to publicly exploitable flaws.

Generated by OpenCVE AI on July 23, 2026 at 14:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LiquidFiles to the latest available version that addresses the HTML injection flaw
  • Limit the ability to upload files containing HTML or script tags to trusted users only, or enforce strict MIME type validation
  • Implement a Content Security Policy that blocks inline script execution to mitigate any residual XSS vectors

Generated by OpenCVE AI on July 23, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via HTML File Upload in LiquidFiles v4.2.7

Tue, 21 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Stored XSS via HTML Injection in LiquidFiles File View

Thu, 16 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Stored XSS via HTML Injection in LiquidFiles File View

Wed, 15 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via HTML Injection in LiquidFiles 4.2.7

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Authenticated Stored XSS via HTML Injection in LiquidFiles 4.2.7

Mon, 13 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via HTML Injection in LiquidFiles 4.2.7

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via HTML Injection in LiquidFiles 4.2.7

Sat, 11 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authenticated HTML Injection Enables Arbitrary JavaScript Execution in LiquidFiles

Fri, 10 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Authenticated HTML Injection Enables Arbitrary JavaScript Execution in LiquidFiles

Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Authenticated File Upload in LiquidFiles

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Authenticated File Upload in LiquidFiles
Weaknesses CWE-79

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Crafted HTML File Upload
Weaknesses CWE-79

Wed, 08 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Crafted HTML File Upload
Weaknesses CWE-79

Tue, 07 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Liquidfiles
Liquidfiles liquidfiles
Vendors & Products Liquidfiles
Liquidfiles liquidfiles

Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.
References

Subscriptions

Liquidfiles Liquidfiles
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T14:43:18.365Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36163

cve-icon Vulnrichment

Updated: 2026-07-09T14:06:14.451Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')