SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-36162

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

An authenticated stored cross-site scripting vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to inject malicious JavaScript or HTML through the Name parameter, potentially compromising user sessions or data integrity. Organizations utilizing this version of LiquidFiles should prioritize remediation to mitigate the risk of exploitation, particularly those handling sensitive information or user interactions through the affected API.

CVE
CVE-2026-36162
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Java

Original NVD Description

An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.