Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Liferay Portal MEDIUM 6.1
CVE-2017-12646

XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.

Fix: after 7.0
Fix from $1,600 2017-08-07
Liferay Portal MEDIUM 6.1
CVE-2017-12647

XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.

Fix: after 7.0
Fix from $1,600 2017-08-07
Liferay Portal MEDIUM 6.1
CVE-2017-12648

XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.

Fix: after 7.0
Fix from $1,600 2017-08-07
Liferay Portal MEDIUM 6.1
CVE-2017-12649

XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.

Fix: after 7.0
Fix from $1,600 2017-08-07
Liferay CRITICAL 9.8
CVE-2016-6517

Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierB…

No fix yet
Fix from $2,300 2017-01-23
Liferay Portal HIGH 8.8
CVE-2010-5327

Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.

Fix: after 6.2.10
Fix from $1,950 2017-01-13
Liferay Portal MEDIUM 6.1
CVE-2016-3670

Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to i…

Fix: after 6.2
Fix from $1,600 2016-06-13
Liferay Portal MEDIUM 6.8
CVE-2011-1571EPSS 8%

Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used…

Fix: after 6.0.5
Fix from $1,600 2011-05-07