Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 5.3
CVE-2024-25605

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 be…

Fix: 7.2 / 7.4.3.5+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 5.4
CVE-2024-25149

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsu…

Fix: 7.2 / 7.4.2+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2023-44308

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote a…

Mitigation only
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.1
CVE-2023-5190

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 befo…

Fix: 7.4.3.102+
Fix from $1,600 2024-02-20
Digital Experience Platform MEDIUM 6.3
CVE-2022-45320

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users…

Fix: 7.2 / 7.4.3.16+
Fix from $1,600 2024-02-20
Digital Experience Platform HIGH 8.1
CVE-2024-25148

In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older u…

Fix: after 7.4.1
Fix from $1,950 2024-02-08
Digital Experience Platform MEDIUM 5.3
CVE-2024-25146

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsu…

Fix: after 7.4.1
Fix from $1,600 2024-02-08
Digital Experience Platform MEDIUM 6.5
CVE-2024-25144

The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6…

Fix: 7.4.3.26+
Fix from $1,600 2024-02-08
Digital Experience Platform MEDIUM 5.4
CVE-2024-25145

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older u…

Fix: 7.2 / 7.4.3.12+
Fix from $1,600 2024-02-07
Digital Experience Platform MEDIUM 6.5
CVE-2024-25143

The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 b…

Fix: 7.2 / 7.2.0+
Fix from $1,600 2024-02-07
Liferay Portal MEDIUM 6.1
CVE-2023-47797

Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers …

Fix: after 7.4.3.95
Fix from $1,600 2023-11-17
Digital Experience Platform MEDIUM 5.4
CVE-2023-42627

Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 updat…

Fix: 7.4.3.92+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 5.4
CVE-2023-42628

Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through …

Fix: 7.4.3.88+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 6.1
CVE-2023-44311

Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay…

Fix: 7.4.3.90+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 5.4
CVE-2023-44310

Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through updat…

Fix: 7.4.3.49+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 5.4
CVE-2023-42629

Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before up…

Fix: 7.4.3.88+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 5.4
CVE-2023-44309

Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 b…

Fix: 7.4.3.53+
Fix from $1,600 2023-10-17
Digital Experience Platform MEDIUM 6.1
CVE-2023-42497

Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4…

Fix: 7.4.3.86+
Fix from $1,600 2023-10-17
Dxp HIGH 8.8
CVE-2023-35030

Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP…

Fix: 7.4.3.77+
Fix from $1,950 2023-06-15
Dxp MEDIUM 6.1
CVE-2023-35029

Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 throu…

Fix: 7.4.3.77+
Fix from $1,600 2023-06-15
Digital Experience Platform MEDIUM 6.1
CVE-2023-3193

Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 up…

Fix: 7.4.3.74+
Fix from $1,600 2023-06-15
Digital Experience Platform HIGH 7.5
CVE-2023-33950

Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerabl…

Fix: after 7.4.3.76
Fix from $1,950 2023-05-24
Digital Experience Platform HIGH 7.5
CVE-2023-33949

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, …

Fix: after 7.2.1
Fix from $1,950 2023-05-24
Digital Experience Platform HIGH 7.5
CVE-2023-33948

The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downlo…

Mitigation only
Fix from $1,950 2023-05-24
Digital Experience Platform HIGH 8.1
CVE-2023-33945

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and …

Fix: after 7.4.3.17
Fix from $1,950 2023-05-24
Digital Experience Platform MEDIUM 6.1
CVE-2023-33944

Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 bef…

Fix: after 7.4.3.68
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 6.1
CVE-2023-33941

Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.…

Fix: after 7.4.3.52
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 5.4
CVE-2023-33942

Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4…

Mitigation only
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 5.4
CVE-2023-33943

Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 …

Fix: after 7.4.3.62
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 6.1
CVE-2023-33938

Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DX…

Fix: after 7.3.7
Fix from $1,600 2023-05-24