Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 6.1
CVE-2025-2536

Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.…

Fix: after 2024.q2.13
Fix from $1,600 2025-03-19
Liferay Portal MEDIUM 6.1
CVE-2024-11993

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote a…

Fix: 7.4 / 7.4.3.39+
Fix from $1,600 2024-12-17
Digital Experience Platform MEDIUM 6.1
CVE-2024-8980

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through u…

Fix: 7.0.6 / 7.1.3+
Fix from $1,600 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-38002

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…

Fix: 7.4.3.112 / 2023.q3.9+
Fix from $1,950 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-26271

Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…

Fix: 7.4.3.112 / 2023.q3.6+
Fix from $1,950 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-26272

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…

Fix: 7.4.3.108 / 2023.q3.6+
Fix from $1,950 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-26273

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 throu…

Fix: 7.4.3.104 / 2023.q3.6+
Fix from $1,950 2024-10-22
Liferay Portal MEDIUM 5.4
CVE-2023-47795

Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q…

Fix: 7.4.3.102+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-25151

The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix …

Fix: 7.2 / 7.4.3.4+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 6.1
CVE-2024-26269

Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before …

Fix: 7.2 / 7.4.3.38+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-25603

Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsup…

Fix: 7.2 / 7.4.3.5+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-26266

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP …

Fix: 7.2 / 7.4.3.14+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 6.1
CVE-2023-42496

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023…

Fix: 7.4.3.98+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 6.1
CVE-2023-42498

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2…

Fix: 7.4.3.98+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 6.1
CVE-2023-40191

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP…

Fix: 7.4.3.98+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-25601

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupp…

Fix: 7.2 / 7.4.3.4+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-25602

Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported v…

Fix: 7.2 / 7.4.3.4+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 6.1
CVE-2024-25147

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay …

Fix: 7.2 / 7.4.2+
Fix from $1,600 2024-02-21
Liferay Portal MEDIUM 5.4
CVE-2024-25152

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Li…

Fix: 7.2 / 7.4.3.4+
Fix from $1,600 2024-02-21
Digital Experience Platform MEDIUM 6.3
CVE-2021-29038

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsuppor…

Fix: 7.2 / 7.3.6+
Fix from $1,600 2024-02-20
Liferay Portal MEDIUM 5.3
CVE-2024-26268

User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 be…

Fix: 7.2 / 7.4.3.27+
Fix from $1,600 2024-02-20
Liferay Portal MEDIUM 5.3
CVE-2024-26270

The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds th…

Fix: 7.4.3.100+
Fix from $1,600 2024-02-20
Liferay Portal MEDIUM 6.5
CVE-2024-26265

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before …

Fix: 7.2 / 7.4.3.16+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 5.4
CVE-2024-25610

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pa…

Fix: 7.2 / 7.4.3.13+
Fix from $1,600 2024-02-20
Liferay Portal MEDIUM 5.3
CVE-2024-26267

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix p…

Fix: 7.2 / 7.4.3.26+
Fix from $1,600 2024-02-20
Digital Experience Platform HIGH 7.5
CVE-2024-25607

The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7…

Fix: 7.2+
Fix from $1,950 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2024-25608

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before up…

Fix: 7.2 / 7.4.3.19+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2024-25609

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pa…

Fix: 7.2 / 7.4.3.13+
Fix from $1,600 2024-02-20
Digital Experience Platform HIGH 8.7
CVE-2024-25606

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12,…

Fix: 7.2 / 7.4.3.8+
Fix from $1,950 2024-02-20
Digital Experience Platform MEDIUM 6.5
CVE-2024-25604

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and …

Fix: 7.2 / 7.4.3.5+
Fix from $1,600 2024-02-20