Unknown · Liquidfiles · CVE-2026-36162
**Name of the Vulnerable Software and Affected Versions**
LiquidFiles version 4.2.7
**Description**
An authenticated stored cross-site scripting (XSS) issue exists in the Upload File Shares API. This allows an attacker to execute arbitrary Javascript or HTML by injecting a crafted payload into the `Name` parameter. Stored XSS occurs when the application receives data from a user and includes that data within its later HTTP responses in an unsafe way.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.