← Back

Digital Experience Platform

digital_experience_platform

Vendor: Liferay • 264 CVEs

CVEs (264)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Sep 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Sep 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of...Show more
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Jul 20, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, becaus...Show more
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Jul 20, 2020
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP...Show more
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.Show less