Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Liquidfiles HIGH 7.3
CVE-2025-56132

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishabl…

Fix: 4.2.0+
Fix from $1,950 2025-09-30
Liquidfiles HIGH 8.8
CVE-2025-46093

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by l…

Fix: 4.1.2+
Fix from $1,950 2025-08-04
Liquidfiles MEDIUM 6.1
CVE-2023-4393

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attac…

Fix: 3.7.14+
Fix from $1,600 2023-10-30
Liquidfiles HIGH 8.8
CVE-2021-43397

LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

Fix: 3.6.3+
Fix from $1,950 2021-11-11
Liquidfiles MEDIUM 5.4
CVE-2021-30140

LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extens…

No fix yet
Fix from $1,600 2021-04-06
Liquidfiles CRITICAL 9.0
CVE-2020-29071

An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the…

Fix: 3.3.19+
Fix from $2,300 2020-11-25
Liquidfiles MEDIUM 6.1
CVE-2020-29072

A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link…

Fix: 3.3.19+
Fix from $1,600 2020-11-25