Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 5.4
CVE-2023-33939

Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 2…

Fix: after 7.4.3.12
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 5.4
CVE-2023-33940

Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 al…

Fix: after 7.4.3.30
Fix from $1,600 2023-05-24
Digital Experience Platform MEDIUM 5.4
CVE-2023-33937

Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pa…

Fix: after 7.3.0
Fix from $1,600 2023-05-24
Liferay Portal CRITICAL 9.8
CVE-2021-33990EPSS 12%

Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…

No fix yet
Fix from $2,300 2023-04-16
Digital Experience Platform MEDIUM 5.9
CVE-2022-42132

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 …

Fix: 7.4.3.5+
Fix from $1,600 2022-11-15
Digital Experience Platform HIGH 7.5
CVE-2022-42123

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before…

Fix: 7.4.3.19+
Fix from $1,950 2022-11-15
Digital Experience Platform HIGH 7.5
CVE-2022-42124

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack …

Fix: 7.4.3.5+
Fix from $1,950 2022-11-15
Digital Experience Platform HIGH 7.5
CVE-2022-42125

Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers t…

Fix: 7.4.3.36+
Fix from $1,950 2022-11-15
Digital Experience Platform MEDIUM 5.3
CVE-2022-42127

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, …

Fix: 7.4.3.37+
Fix from $1,600 2022-11-15
Digital Experience Platform MEDIUM 5.3
CVE-2022-42128

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows rem…

Fix: 7.4.3.5+
Fix from $1,600 2022-11-15
Dxp CRITICAL 9.8
CVE-2022-42120

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…

Fix: after 7.4.3.16
Fix from $2,300 2022-11-15
Dxp CRITICAL 9.8
CVE-2022-42122

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…

Mitigation only
Fix from $2,300 2022-11-15
Liferay Portal HIGH 8.8
CVE-2022-42121

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pa…

Fix: after 7.4.3.4
Fix from $1,950 2022-11-15
Liferay Portal MEDIUM 6.1
CVE-2022-42118

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27,…

Fix: after 7.4.2
Fix from $1,600 2022-11-15
Liferay Portal MEDIUM 5.4
CVE-2022-42119

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Li…

Fix: after 7.4.2
Fix from $1,600 2022-11-15
Liferay Portal MEDIUM 5.4
CVE-2022-42111

A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 befor…

Fix: after 7.4.2
Fix from $1,600 2022-11-15
Liferay Portal MEDIUM 6.1
CVE-2022-42110

A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27,…

Fix: after 7.4.2
Fix from $1,600 2022-11-15
Dxp MEDIUM 5.4
CVE-2022-38901

A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10…

Fix: 7.3+
Fix from $1,600 2022-10-19
Dxp MEDIUM 6.1
CVE-2022-42113

A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 thro…

Fix: 7.4.3.37+
Fix from $1,600 2022-10-18
Dxp MEDIUM 6.1
CVE-2022-42116

A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Li…

Fix: 7.3 / 7.4.3.15+
Fix from $1,600 2022-10-18
Dxp MEDIUM 6.1
CVE-2022-42117

A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update …

Fix: 7.3+
Fix from $1,600 2022-10-18
Digital Experience Platform MEDIUM 5.4
CVE-2022-42112

A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 be…

Fix: 7.2 / 7.4.3.25+
Fix from $1,600 2022-10-18
Dxp MEDIUM 5.4
CVE-2022-42114

A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.…

Fix: 7.4 / 7.4.3.37+
Fix from $1,600 2022-10-18
Liferay Portal MEDIUM 5.4
CVE-2022-42115

Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote att…

Fix: 7.4.3.37+
Fix from $1,600 2022-10-18
Dxp MEDIUM 5.4
CVE-2022-38902

A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows …

Fix: after 7.4.0
Fix from $1,600 2022-10-13
Liferay Portal MEDIUM 5.3
CVE-2022-41414

An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site …

Fix: after 7.4.2
Fix from $1,600 2022-10-07
Liferay Portal HIGH 7.5
CVE-2022-28981

Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside…

Fix: after 7.4.2
Fix from $1,950 2022-09-22
Dxp MEDIUM 6.5
CVE-2022-38512

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allow…

Fix: after 7.4.3.36
Fix from $1,600 2022-09-22
Dxp MEDIUM 6.1
CVE-2022-28980

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scri…

Fix: 7.4.3.5+
Fix from $1,600 2022-09-22
Digital Experience Platform MEDIUM 6.1
CVE-2022-28977

HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack …

Fix: 7.4.3.4+
Fix from $1,600 2022-09-22