Liferay
liferay
338 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (338)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Mar 20, 2025 5.1 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 16, 2025 Mar 19, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 throug...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Dec 17, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions...Show more |
1Liferay 2Digital Experience Platform Liferay PortalMar 28, 2025 Dec 17, 2024 4.6 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name fiel...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Oct 22, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 G...Show more |
1Liferay 2Digital Experience Platform Liferay PortalSep 10, 2025 Oct 22, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check us...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Oct 22, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Oct 22, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Oct 22, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through updat...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authentica...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied d...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsu...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 befor...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attack...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote att...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before f...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older...Show more |