Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
CVE-2026-36162
CVE-2026-36162
Description
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
Affected products
1- Range: <4.2.7
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.