Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Digital Experience Platform MEDIUM 6.1
CVE-2021-29049

Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack…

Patch available
Fix from $1,600 2021-06-09
Digital Experience Platform MEDIUM 6.1
CVE-2021-29048

Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fi…

Mitigation only
Fix from $1,600 2021-05-17
Digital Experience Platform MEDIUM 6.1
CVE-2021-29051

Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before …

Fix: after 7.3.5
Fix from $1,600 2021-05-17
Dxp HIGH 8.8
CVE-2021-29053

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbi…

Mitigation only
Fix from $1,950 2021-05-17
Digital Experience Platform MEDIUM 6.1
CVE-2021-29044

Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Life…

Fix: after 7.3.5
Fix from $1,600 2021-05-17
Dxp MEDIUM 6.1
CVE-2021-29045

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay …

Fix: after 7.3.5
Fix from $1,600 2021-05-17
Dxp MEDIUM 6.1
CVE-2021-29046

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix p…

Mitigation only
Fix from $1,600 2021-05-17
Digital Experience Platform MEDIUM 5.9
CVE-2021-29043

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10…

Fix: after 7.3.5
Fix from $1,600 2021-05-17
Dxp HIGH 7.5
CVE-2021-29047

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is…

Fix: 7.3+
Fix from $1,950 2021-05-16
Dxp MEDIUM 6.5
CVE-2021-29041

Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated atta…

Fix: 7.3+
Fix from $1,600 2021-05-16
Digital Experience Platform MEDIUM 5.3
CVE-2021-29040

The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 …

Fix: 7.0+
Fix from $1,600 2021-05-16
Liferay Portal MEDIUM 6.1
CVE-2021-29039

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inje…

Mitigation only
Fix from $1,600 2021-05-16
Liferay Portal MEDIUM 6.1
CVE-2020-25476

Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. A…

Patch available
Fix from $1,600 2021-01-07
Digital Experience Platform MEDIUM 5.3
CVE-2020-15840

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regex…

Fix: 7.3.1+
Fix from $1,600 2020-09-24
Digital Experience Platform MEDIUM 6.5
CVE-2020-15839

Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data PO…

Fix: 7.3.3+
Fix from $1,600 2020-09-22
Liferay Portal HIGH 7.5
CVE-2020-24554

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote a…

Fix: 7.3.3+
Fix from $1,950 2020-09-01
Digital Experience Platform HIGH 8.8
CVE-2020-15841

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connec…

Fix: 7.3.0+
Fix from $1,950 2020-07-20
Digital Experience Platform HIGH 8.1
CVE-2020-15842

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle atta…

Fix: 7.3.0+
Fix from $1,950 2020-07-20
Liferay Portal HIGH 8.8
CVE-2020-13445

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r…

Patch available
Fix from $1,950 2020-06-10
Liferay Portal MEDIUM 6.5
CVE-2020-13444

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the info…

Patch available
Fix from $1,600 2020-06-10
Liferay Portal CRITICAL 9.8
CVE-2020-7961 KEVEPSS 100%

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS…

Fix: 7.2.1+
Fix from $2,300 2020-03-20
Liferay Portal MEDIUM 5.4
CVE-2020-7934

In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnera…

Fix: after 7.2.1
Fix from $1,600 2020-01-28
Liferay Portal CRITICAL 9.8
CVE-2019-16891EPSS 46%

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

Fix: after 6.0.6
Fix from $2,300 2019-10-04
Liferay Portal MEDIUM 6.1
CVE-2019-16147

Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.

Fix: 7.2.0+
Fix from $1,600 2019-09-09
Liferay Portal HIGH 7.2
CVE-2019-11444EPSS 13%

An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be e…

No fix yet
Fix from $1,950 2019-04-22
Liferay Portal HIGH 8.8
CVE-2018-10795

Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatica…

Fix: after 6.2.5
Fix from $1,950 2018-05-07
Liferay Portal MEDIUM 6.1
CVE-2017-1000425

Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject …

Fix: 7.0.3_ga4+
Fix from $1,600 2018-01-02
Liferay Portal MEDIUM 6.1
CVE-2017-17868

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

No fix yet
Fix from $1,600 2017-12-27
Liferay Portal MEDIUM 6.1
CVE-2016-10404

XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resou…

Fix: after 7.0
Fix from $1,600 2017-08-07
Liferay Portal MEDIUM 6.1
CVE-2017-12645

XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.

Fix: after 7.0
Fix from $1,600 2017-08-07