Liquidfiles develops a focused secure file-transfer and collaboration platform that, despite a narrow product footprint, ranks among more prominent vendors in the landscape and skews toward serious severity outcomes. Its recurring vulnerabilities center on web application input handling and authentication, particularly cross-site scripting, authentication bypass, output encoding flaws, and injection weaknesses that reflect the complexity of building secure file-exchange and user-management logic, and the vendor's disclosures frequently acquire public exploit code. Defenders should monitor this vendor's releases closely given the sensitive nature of file-transfer appliances and the severity character of its exposure; current exploitation activity and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liquidfiles over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56132HIGH LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and inval | Sep 30, 2025 | 7.3 | 35 | NO | YES |
CVE-2025-46093HIGH LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feat | Aug 4, 2025 | 8.8 | 31 | NO | NO |
CVE-2021-43397HIGH LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. | Nov 11, 2021 | 8.8 | 29 | NO | NO |
CVE-2026-12673MEDIUM Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modi | Jun 20, 2026 | 5.9 | 25 | NO | NO |
CVE-2020-29071CRITICAL An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when | Nov 25, 2020 | 9.0 | 22 | NO | NO |
CVE-2023-4393MEDIUM HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization. | Oct 30, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-30140MEDIUM LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML | Apr 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-29072MEDIUM A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation c | Nov 25, 2020 | 6.1 | 20 | NO | NO |
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript. | Aug 4, 2025 | 3.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liquidfiles.
Media articles that mention a CVE ID that affects a product developed by Liquidfiles — matched by CVE ID, not by vendor name.