Liferay
liferay
338 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (338)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupp...Show more |
1Liferay 2Digital Experience Platform Liferay PortalMay 13, 2025 Feb 20, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page,...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 20, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 20, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions a...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 20, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 20, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2024 Feb 20, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does n...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2024 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2024 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be c...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2024 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and o...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 11, 2024 Feb 20, 2024 N/A· v4 8.7 HIGH· v3 N/A· v2 XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attacker...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Feb 20, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users vie...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Feb 20, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, wh...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Feb 20, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions...Show more |
1Liferay 2Digital Experience Platform Liferay PortalDec 10, 2024 Feb 20, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site...Show more |
1Liferay 1Digital Experience Platform Jan 28, 2025 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_life...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJan 28, 2025 Feb 20, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to red...Show more |
1Liferay 2Digital Experience Platform Liferay PortalMar 28, 2025 Feb 20, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page. |
1Liferay 3Digital Experience Platform DxpLiferay PortalMay 13, 2025 Feb 8, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when...Show more |
1Liferay 3Digital Experience Platform DxpLiferay PortalMay 13, 2025 Feb 8, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether...Show more |