Skip to main content
CRITICAL

CVE-2020-29071

CVSS v3

9

CRITICAL

EPSS Score

1.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.

Technical details

Published
2020-11-25

Frequently asked questions

What is CVE-2020-29071?

An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.

Is CVE-2020-29071 actively exploited?

Active exploitation of CVE-2020-29071 has not been confirmed. Its EPSS score was 1.7% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-29071?

CVE-2020-29071 has a CVSS v3 base score of 9 (CRITICAL severity).

Is CVE-2020-29071 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key