SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-36163

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to upload malicious HTML files, enabling the execution of arbitrary JavaScript in the victim's browser. This could lead to unauthorized actions or data exposure for users interacting with the compromised content. Organizations using this version of LiquidFiles should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-36163
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Java

Original NVD Description

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.