Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aleksander Młodak

Researcher fromSecuRing
#23223of 56,335
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-56276
5.4
2026-07-07
Unknown · Liquidfiles · CVE-2026-36162
**Name of the Vulnerable Software and Affected Versions** LiquidFiles version 4.2.7 **Description** An authenticated stored cross-site scripting (XSS) issue exists in the Upload File Shares API. This allows an attacker to execute arbitrary Javascript or HTML by injecting a crafted payload into the `Name` parameter. Stored XSS occurs when the application receives data from a user and includes that data within its later HTTP responses in an unsafe way. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-56277
5.4
2026-07-07
Unknown · Liquidfiles · CVE-2026-36163
**Name of the Vulnerable Software and Affected Versions** LiquidFiles version 4.2.7 **Description** An HTML injection issue exists in the file view endpoint. This allows authenticated attackers to execute arbitrary JavaScript within the victim's browser by uploading a specially crafted HTML file and inducing user interaction with it. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.