Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-25605 The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 be… Digital Experience Platform 7.2 / 7.4.3.5+ Fix from $1,6002024-02-20 MEDIUM 5.4 CVE-2024-25149 Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsu… Digital Experience Platform 7.2 / 7.4.2+ Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2023-44308 Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote a… Digital Experience Platform Mitigation only Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2023-5190 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 befo… Digital Experience Platform 7.4.3.102+ Fix from $1,6002024-02-20 MEDIUM 6.3 CVE-2022-45320 Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users… Digital Experience Platform 7.2 / 7.4.3.16+ Fix from $1,6002024-02-20 HIGH 8.1 CVE-2024-25148 In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older u… Digital Experience Platform after 7.4.1 Fix from $1,9502024-02-08 MEDIUM 5.3 CVE-2024-25146 Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsu… Digital Experience Platform after 7.4.1 Fix from $1,6002024-02-08 MEDIUM 6.5 CVE-2024-25144 The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6… Digital Experience Platform 7.4.3.26+ Fix from $1,6002024-02-08 MEDIUM 5.4 CVE-2024-25145 Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older u… Digital Experience Platform 7.2 / 7.4.3.12+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-25143 The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 b… Digital Experience Platform 7.2 / 7.2.0+ Fix from $1,6002024-02-07 MEDIUM 6.1 CVE-2023-47797 Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers … Liferay Portal after 7.4.3.95 Fix from $1,6002023-11-17 MEDIUM 5.4 CVE-2023-42627 Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 updat… Digital Experience Platform 7.4.3.92+ Fix from $1,6002023-10-17 MEDIUM 5.4 CVE-2023-42628 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through … Digital Experience Platform 7.4.3.88+ Fix from $1,6002023-10-17 MEDIUM 6.1 CVE-2023-44311 Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay… Digital Experience Platform 7.4.3.90+ Fix from $1,6002023-10-17 MEDIUM 5.4 CVE-2023-44310 Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through updat… Digital Experience Platform 7.4.3.49+ Fix from $1,6002023-10-17 MEDIUM 5.4 CVE-2023-42629 Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before up… Digital Experience Platform 7.4.3.88+ Fix from $1,6002023-10-17 MEDIUM 5.4 CVE-2023-44309 Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 b… Digital Experience Platform 7.4.3.53+ Fix from $1,6002023-10-17 MEDIUM 6.1 CVE-2023-42497 Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4… Digital Experience Platform 7.4.3.86+ Fix from $1,6002023-10-17 HIGH 8.8 CVE-2023-35030 Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP… Dxp 7.4.3.77+ Fix from $1,9502023-06-15 MEDIUM 6.1 CVE-2023-35029 Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 throu… Dxp 7.4.3.77+ Fix from $1,6002023-06-15 MEDIUM 6.1 CVE-2023-3193 Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 up… Digital Experience Platform 7.4.3.74+ Fix from $1,6002023-06-15 HIGH 7.5 CVE-2023-33950 Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerabl… Digital Experience Platform after 7.4.3.76 Fix from $1,9502023-05-24 HIGH 7.5 CVE-2023-33949 In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, … Digital Experience Platform after 7.2.1 Fix from $1,9502023-05-24 HIGH 7.5 CVE-2023-33948 The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downlo… Digital Experience Platform Mitigation only Fix from $1,9502023-05-24 HIGH 8.1 CVE-2023-33945 SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and … Digital Experience Platform after 7.4.3.17 Fix from $1,9502023-05-24 MEDIUM 6.1 CVE-2023-33944 Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 bef… Digital Experience Platform after 7.4.3.68 Fix from $1,6002023-05-24 MEDIUM 6.1 CVE-2023-33941 Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.… Digital Experience Platform after 7.4.3.52 Fix from $1,6002023-05-24 MEDIUM 5.4 CVE-2023-33942 Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4… Digital Experience Platform Mitigation only Fix from $1,6002023-05-24 MEDIUM 5.4 CVE-2023-33943 Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 … Digital Experience Platform after 7.4.3.62 Fix from $1,6002023-05-24 MEDIUM 6.1 CVE-2023-33938 Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DX… Digital Experience Platform after 7.3.7 Fix from $1,6002023-05-24