CVE-2026-36163 is an HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7. Authenticated attackers can execute arbitrary JavaScript in the context of the victim's browser by uploading and interacting with a crafted HTML file. This vulnerability has a medium defensive priority, and users of LiquidFiles v4.2.7 should be aware of this vulnerability and take steps to mitigate it. The v [truncated]
CVE-2026-36162 is an authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7. The vulnerability allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter. This vulnerability affects users of LiquidFiles v4.2.7, who should be aware of this vulnerability and take steps to mitigate it. The CVE rec [truncated]
CVE-2026-12673 is a medium-severity vulnerability in Liquidfiles versions before 4.2.12. It is caused by a broken access control issue that allows privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group. The CVSS score for this vulnerability is 5.9. The vulnerability was published on June 20, 2026. Defenders should assess t [truncated]