Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 6.1
CVE-2023-44308

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote a…

Mitigation only
Fix from $1,600 2024-02-20
Digital Experience Platform HIGH 7.5
CVE-2023-33948

The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downlo…

Mitigation only
Fix from $1,950 2023-05-24
Digital Experience Platform MEDIUM 5.4
CVE-2023-33942

Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4…

Mitigation only
Fix from $1,600 2023-05-24
Liferay Portal CRITICAL 9.8
CVE-2021-33990EPSS 12%

Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…

No fix yet
Fix from $2,300 2023-04-16
Dxp CRITICAL 9.8
CVE-2022-42122

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…

Mitigation only
Fix from $2,300 2022-11-15
Liferay Portal HIGH 7.2
CVE-2020-28884

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a…

Mitigation only
Fix from $1,950 2022-01-28
Liferay Portal HIGH 7.2
CVE-2020-28885

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo …

Mitigation only
Fix from $1,950 2022-01-28
Liferay Portal MEDIUM 6.1
CVE-2021-35463

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script…

Mitigation only
Fix from $1,600 2021-08-04
Digital Experience Platform MEDIUM 6.1
CVE-2021-29048

Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fi…

Mitigation only
Fix from $1,600 2021-05-17
Dxp HIGH 8.8
CVE-2021-29053

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbi…

Mitigation only
Fix from $1,950 2021-05-17
Dxp MEDIUM 6.1
CVE-2021-29046

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix p…

Mitigation only
Fix from $1,600 2021-05-17
Liferay Portal MEDIUM 6.1
CVE-2021-29039

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inje…

Mitigation only
Fix from $1,600 2021-05-16
Liferay Portal HIGH 7.2
CVE-2019-11444EPSS 13%

An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be e…

No fix yet
Fix from $1,950 2019-04-22
Liferay Portal MEDIUM 6.1
CVE-2017-17868

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

No fix yet
Fix from $1,600 2017-12-27
Liferay CRITICAL 9.8
CVE-2016-6517

Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierB…

No fix yet
Fix from $2,300 2017-01-23