Liferay
liferay
338 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (338)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 19, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript c...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 19, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 19, 2025 Aug 19, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 19, 2025 Aug 19, 2025 4.6 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 202...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 19, 2025 Aug 18, 2025 6.9 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 19, 2025 Aug 18, 2025 4.8 MEDIUM· v4 2.7 LOW· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA throu...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 18, 2025 2.3 LOW· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's na...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 12, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 throu...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 12, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 throu...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 12, 2025 6.9 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 t...Show more |
1Liferay 2Digital Experience Platform Liferay PortalApr 29, 2026 Aug 9, 2025 5.1 MEDIUM· v4 5.0 MEDIUM· v3 N/A· v2 SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13,...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Aug 9, 2025 5.3 MEDIUM· v4 8.6 HIGH· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through u...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 8, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 4, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 15, 2025 Aug 4, 2025 2.0 LOW· v4 6.1 MEDIUM· v3 N/A· v2 The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 12, 2025 Jun 16, 2025 8.6 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attack...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Jun 16, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP ses...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Jun 16, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 May 6, 2025 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 throu...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Apr 17, 2025 4.8 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0...Show more |