Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 6.1
CVE-2022-28979

Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to …

Fix: 7.4.3.4+
Fix from $1,600 2022-09-22
Dxp MEDIUM 6.1
CVE-2022-28982

A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to exe…

Fix: 7.4.3.4+
Fix from $1,600 2022-09-22
Digital Experience Platform MEDIUM 5.4
CVE-2022-28978

Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and L…

Fix: 7.4.2+
Fix from $1,600 2022-09-22
Digital Experience Platform MEDIUM 6.1
CVE-2022-26596

Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Lifera…

Fix: after 7.3.3
Fix from $1,600 2022-04-25
Digital Experience Platform MEDIUM 6.1
CVE-2022-26597

Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 bef…

Fix: 7.3+
Fix from $1,600 2022-04-25
Digital Experience Platform MEDIUM 5.4
CVE-2022-26593

Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 b…

Fix: 7.3 / 7.3.7+
Fix from $1,600 2022-04-19
Liferay Portal MEDIUM 6.1
CVE-2022-26594

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote att…

Fix: 7.3.7+
Fix from $1,600 2022-04-15
Digital Experience Platform MEDIUM 5.4
CVE-2021-38265

Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web scr…

Fix: after 7.3.6
Fix from $1,600 2022-03-03
Digital Experience Platform MEDIUM 5.4
CVE-2021-38267

Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before…

Fix: 7.3+
Fix from $1,600 2022-03-03
Liferay Portal MEDIUM 5.4
CVE-2021-38269

Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pac…

Fix: after 7.3.6
Fix from $1,600 2022-03-03
Digital Experience Platform MEDIUM 5.3
CVE-2022-25146

The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of …

Fix: 7.4.3.9+
Fix from $1,600 2022-03-03
Liferay Portal MEDIUM 6.1
CVE-2021-38263

Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pa…

Fix: after 7.3.2
Fix from $1,600 2022-03-03
Liferay Portal MEDIUM 6.1
CVE-2021-38264

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary …

Patch available
Fix from $1,600 2022-03-03
Liferay Portal HIGH 7.5
CVE-2021-38266

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pac…

Fix: after 7.2.1
Fix from $1,950 2022-03-02
Digital Experience Platform MEDIUM 6.5
CVE-2021-38268

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fi…

Fix: 7.2.1 / 7.3.7+
Fix from $1,600 2022-03-02
Liferay Portal HIGH 7.2
CVE-2020-28884

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a…

Mitigation only
Fix from $1,950 2022-01-28
Liferay Portal HIGH 7.2
CVE-2020-28885

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo …

Mitigation only
Fix from $1,950 2022-01-28
Digital Experience Platform HIGH 7.5
CVE-2021-33338

The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in…

Fix: after 7.3.2
Fix from $1,950 2021-08-04
Digital Experience Platform MEDIUM 6.1
CVE-2021-33337

Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.…

Fix: after 7.3.4
Fix from $1,600 2021-08-04
Liferay Portal MEDIUM 6.1
CVE-2021-35463

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script…

Mitigation only
Fix from $1,600 2021-08-04
Digital Experience Platform MEDIUM 5.4
CVE-2021-33336

Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack…

Fix: 7.3.4+
Fix from $1,600 2021-08-04
Digital Experience Platform HIGH 7.2
CVE-2021-33335

Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows re…

Fix: 7.3.5+
Fix from $1,950 2021-08-03
Digital Experience Platform MEDIUM 6.3
CVE-2021-33333

The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pac…

Fix: 7.3.3+
Fix from $1,600 2021-08-03
Digital Experience Platform MEDIUM 6.1
CVE-2021-33331

Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix…

Fix: 7.3.2+
Fix from $1,600 2021-08-03
Digital Experience Platform MEDIUM 6.1
CVE-2021-33332

Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pa…

Fix: 7.3.3+
Fix from $1,600 2021-08-03
Dxp HIGH 7.5
CVE-2021-33321

Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email add…

Fix: 7.3 / 7.3.3+
Fix from $1,950 2021-08-03
Digital Experience Platform HIGH 7.5
CVE-2021-33322

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens…

Fix: 7.3.1+
Fix from $1,950 2021-08-03
Digital Experience Platform HIGH 7.5
CVE-2021-33323

The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves f…

Fix: 7.3.1+
Fix from $1,950 2021-08-03
Digital Experience Platform MEDIUM 6.1
CVE-2021-33326

Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 b…

Fix: 7.3.5+
Fix from $1,600 2021-08-03
Digital Experience Platform MEDIUM 5.4
CVE-2021-33328

Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before…

Fix: 7.3.5+
Fix from $1,600 2021-08-03