Liferay
liferay
338 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (338)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 22, 2025 6.7 MEDIUM· v4 2.7 LOW· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 22, 2025 5.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 22, 2025 5.3 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 18, 2025 Aug 22, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 t...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 22, 2025 5.3 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 21, 2025 2.1 LOW· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 thr...Show more |
1Liferay 1Digital Experience Platform Dec 12, 2025 Aug 21, 2025 4.8 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by ch...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Aug 21, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Aug 21, 2025 6.9 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 <!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.15, 2025.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Aug 21, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.13, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 t...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Aug 20, 2025 4.8 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Aug 20, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 20, 2025 7.1 HIGH· v4 6.8 MEDIUM· v3 N/A· v2 Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through u...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 18, 2025 Aug 20, 2025 5.1 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 20, 2025 5.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 20, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 20, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 19, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 thr...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 19, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 19, 2025 6.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024...Show more |