Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Liquidfiles

First CVE: Nov 25, 2020Active for: 6 yearsTotal CVEs: 9

Liquidfiles develops a focused secure file-transfer and collaboration platform that, despite a narrow product footprint, ranks among more prominent vendors in the landscape and skews toward serious severity outcomes. Its recurring vulnerabilities center on web application input handling and authentication, particularly cross-site scripting, authentication bypass, output encoding flaws, and injection weaknesses that reflect the complexity of building secure file-exchange and user-management logic, and the vendor's disclosures frequently acquire public exploit code. Defenders should monitor this vendor's releases closely given the sensitive nature of file-transfer appliances and the severity character of its exposure; current exploitation activity and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Liquidfiles over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 25, 2020
5 years ago
Most Recent CVE
Jun 20, 2026
34 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-56132HIGH
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and inval
Sep 30, 20257.335NOYES
CVE-2025-46093HIGH
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feat
Aug 4, 20258.831NONO
CVE-2021-43397HIGH
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
Nov 11, 20218.829NONO
CVE-2026-12673MEDIUM
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modi
Jun 20, 20265.925NONO
CVE-2020-29071CRITICAL
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when
Nov 25, 20209.022NONO
CVE-2023-4393MEDIUM
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
Oct 30, 20236.121NONO
CVE-2021-30140MEDIUM
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML
Apr 6, 20215.420NONO
CVE-2020-29072MEDIUM
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation c
Nov 25, 20206.120NONO
CVE-2025-46094LOW
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.
Aug 4, 20253.816NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
44%
33%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low4 (44.4%)
High2 (22.2%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Liquidfiles.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Liquidfiles — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Liquidfiles's Products

View all 3 CNAs →

Top CWEs