Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-44308 Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote a… Digital Experience Platform Mitigation only Fix from $1,6002024-02-20 HIGH 7.5 CVE-2023-33948 The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downlo… Digital Experience Platform Mitigation only Fix from $1,9502023-05-24 MEDIUM 5.4 CVE-2023-33942 Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4… Digital Experience Platform Mitigation only Fix from $1,6002023-05-24 CRITICAL 9.8 CVE-2021-33990EPSS 12% Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b… Liferay Portal No fix yet Fix from $2,3002023-04-16 CRITICAL 9.8 CVE-2022-42122 A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to… Dxp Mitigation only Fix from $2,3002022-11-15 HIGH 7.2 CVE-2020-28884 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a… Liferay Portal Mitigation only Fix from $1,9502022-01-28 HIGH 7.2 CVE-2020-28885 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo … Liferay Portal Mitigation only Fix from $1,9502022-01-28 MEDIUM 6.1 CVE-2021-35463 Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script… Liferay Portal Mitigation only Fix from $1,6002021-08-04 MEDIUM 6.1 CVE-2021-29048 Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fi… Digital Experience Platform Mitigation only Fix from $1,6002021-05-17 HIGH 8.8 CVE-2021-29053 Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbi… Dxp Mitigation only Fix from $1,9502021-05-17 MEDIUM 6.1 CVE-2021-29046 Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix p… Dxp Mitigation only Fix from $1,6002021-05-17 MEDIUM 6.1 CVE-2021-29039 Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inje… Liferay Portal Mitigation only Fix from $1,6002021-05-16 HIGH 7.2 CVE-2019-11444EPSS 13% An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be e… Liferay Portal No fix yet Fix from $1,9502019-04-22 MEDIUM 6.1 CVE-2017-17868 In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag. Liferay Portal No fix yet Fix from $1,6002017-12-27 CRITICAL 9.8 CVE-2016-6517 Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierB… Liferay No fix yet Fix from $2,3002017-01-23