#liquidfiles
The lobbyists are strong! But we can fight against them. ;-)
#linux #opensource #nextcloud #openexchange #proxmox #liquidfiles #thunderbird #firefox #brave #gnupg #python #seppmail #mullvad #pfsense #fastviewer #selfhosting #onprem #protondrive #openproject #drawref="https://draw.io" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">draw.io #wazuh
March 14, 2025 at 12:07 PM
🚨 EUVD-2026-42152
📊 n/a

📝 An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript o...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42152

#cybersecurity #infosec #cve #euvd
July 8, 2026 at 4:03 AM
🚨 EUVD-2026-42153
📊 n/a

📝 An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the vi...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42153

#cybersecurity #infosec #cve #euvd
July 8, 2026 at 4:03 AM
Daily IT Security Digest — 2026-07-08
Vulnerabilities Database posted five new vulnerabilities: LiquidFiles v4.2.7 has both HTML injection and authenticated stored XSS in its file upload/view endpoints; Trueview T18161- AF security camera has auth bypass via hardcoded credentials; Fire-Boltt
July 8, 2026 at 5:02 AM
CVE-2026-36163 - LiquidFiles Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2026-36163

Published : July 7, 2026, 11:16 p.m. | 31 minutes ago

Description : An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attacke...
CVE-2026-36163 - LiquidFiles Stored Cross-Site Scripting Vulnerability
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.
cvefeed.io
July 8, 2026 at 12:23 AM
CVE-2026-36162 - LiquidFiles Upload File Shares API Stored Cross-Site Scripting
CVE ID : CVE-2026-36162

Published : July 7, 2026, 11:16 p.m. | 31 minutes ago

Description : An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of L...
CVE-2026-36162 - LiquidFiles Upload File Shares API Stored Cross-Site Scripting
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
cvefeed.io
July 8, 2026 at 12:25 AM
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in ... LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The a...

Origin | Interest | Match
CVE-2025-56132 | THREATINT
CVE-2025-56132: LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence...
cve.threatint.eu
September 30, 2025 at 8:14 PM
CVE-2026-12673 - Liquidfiles Broken Access Control Privilege Escalation
CVE ID : CVE-2026-12673

Published : June 20, 2026, 12:36 p.m. | 3 hours, 7 minutes ago

Description : Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting...
CVE-2026-12673 - Liquidfiles Broken Access Control Privilege Escalation
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group.
cvefeed.io
June 20, 2026 at 4:14 PM
「LiquidFiles」に脆弱性 - FTP経由で権限取得のおそれ

LiquidFilesが提供するファイル転送ソリューション「LiquidFiles」に関する複数の脆弱性が明らかとなった。詳細や概念実証なども公開されている。

同ソフトウェアにおいて、権限昇格の脆弱性「CVE-2025-46093」やパストラバーサルによってスクリプトの実行が可能となる脆弱性「CVE-2025-46094」が明らかとなったもの。

脆弱性の悪用には認証が必要となるが、FTP機能において認証され、一定の権限を持つユーザーがファイルの権限を設定でき、組み合わせることでroot権限により任意のコードを実行...
【セキュリティ ニュース】「LiquidFiles」に脆弱性 - FTP経由で権限取得のおそれ(1ページ目 / 全1ページ):Security NEXT
LiquidFilesが提供するファイル転送ソリューション「LiquidFiles」に関する複数の脆弱性が明らかとなった。詳細や概念実証なども公開されている。 :Security NEXT
www.security-next.com
August 7, 2025 at 11:42 PM
【セキュリティ ニュース】「LiquidFiles」に脆弱性 – FTP経由で権限取得のおそれ(1ページ目 / 全1ページ):Security NEXT

https://www.yayafa.com/2468299/

LiquidFilesが提供するファイル転送ソリューション「LiquidFiles」に関する複数の脆弱性が明らかとなった。詳細や概念実証なども公開されている。 同ソフトウェアにおいて、権限昇格の脆弱性「CVE-2025- [...]
【セキュリティ ニュース】「LiquidFiles」に脆弱性 - FTP経由で権限取得のおそれ(1ページ目 / 全1ページ):Security NEXT - YAYAFA
LiquidFilesが提供するファイル転送ソリューション「LiquidFiles」に関する複数の脆弱性が明らかとなった。詳細や概念実証なども公開されている。
www.yayafa.com
August 6, 2025 at 11:40 AM
🚨 EUVD-2026-38111
📊 5.9/10
🏢 LiquidFiles

📝 Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondar...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38111

#cybersecurity #infosec #cve #euvd
June 20, 2026 at 3:00 PM
Liquidfiles versions before 4.2.12 are affected by a broken access control vu... Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege esca...

Origin | Interest | Match
CVE-2026-12673 | THREATINT
CVE-2026-12673: Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group.
cve.threatint.eu
June 20, 2026 at 2:01 PM