CVEs (319)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Nov 1, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does n...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Nov 1, 2025 4.6 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through up...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 31, 2025 4.6 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 31, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through u...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 11, 2025 Oct 30, 2025 4.8 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 11, 2025 Oct 30, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and o...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 30, 2025 6.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 G...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 8, 2025 Oct 27, 2025 6.9 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit acces...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 27, 2025 7.0 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 27, 2025 6.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 27, 2025 7.1 HIGH· v4 7.5 HIGH· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from He...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 27, 2025 4.6 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92,...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 27, 2025 4.8 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote atta...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Oct 27, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 23, 2025 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, an...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Oct 23, 2025 2.0 LOW· v4 6.1 MEDIUM· v3 N/A· v2 Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through...Show more |
1Liferay 2Digital Experience Platform Liferay PortalNov 10, 2025 Oct 23, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly rest...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2025 Oct 22, 2025 2.0 LOW· v4 6.5 MEDIUM· v3 N/A· v2 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 thro...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2025 Oct 22, 2025 4.8 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Oct 21, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.Q3.2, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 throu...Show more |