Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-33939 Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 2… Digital Experience Platform after 7.4.3.12 Fix from $1,6002023-05-24 MEDIUM 5.4 CVE-2023-33940 Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 al… Digital Experience Platform after 7.4.3.30 Fix from $1,6002023-05-24 MEDIUM 5.4 CVE-2023-33937 Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pa… Digital Experience Platform after 7.3.0 Fix from $1,6002023-05-24 CRITICAL 9.8 CVE-2021-33990EPSS 12% Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b… Liferay Portal No fix yet Fix from $2,3002023-04-16 MEDIUM 5.9 CVE-2022-42132 The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 … Digital Experience Platform 7.4.3.5+ Fix from $1,6002022-11-15 HIGH 7.5 CVE-2022-42123 A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before… Digital Experience Platform 7.4.3.19+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-42124 ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack … Digital Experience Platform 7.4.3.5+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-42125 Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers t… Digital Experience Platform 7.4.3.36+ Fix from $1,9502022-11-15 MEDIUM 5.3 CVE-2022-42127 The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, … Digital Experience Platform 7.4.3.37+ Fix from $1,6002022-11-15 MEDIUM 5.3 CVE-2022-42128 The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows rem… Digital Experience Platform 7.4.3.5+ Fix from $1,6002022-11-15 CRITICAL 9.8 CVE-2022-42120 A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up… Dxp after 7.4.3.16 Fix from $2,3002022-11-15 CRITICAL 9.8 CVE-2022-42122 A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to… Dxp Mitigation only Fix from $2,3002022-11-15 HIGH 8.8 CVE-2022-42121 A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pa… Liferay Portal after 7.4.3.4 Fix from $1,9502022-11-15 MEDIUM 6.1 CVE-2022-42118 A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27,… Liferay Portal after 7.4.2 Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-42119 Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Li… Liferay Portal after 7.4.2 Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-42111 A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 befor… Liferay Portal after 7.4.2 Fix from $1,6002022-11-15 MEDIUM 6.1 CVE-2022-42110 A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27,… Liferay Portal after 7.4.2 Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-38901 A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10… Dxp 7.3+ Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-42113 A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 thro… Dxp 7.4.3.37+ Fix from $1,6002022-10-18 MEDIUM 6.1 CVE-2022-42116 A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Li… Dxp 7.3 / 7.4.3.15+ Fix from $1,6002022-10-18 MEDIUM 6.1 CVE-2022-42117 A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update … Dxp 7.3+ Fix from $1,6002022-10-18 MEDIUM 5.4 CVE-2022-42112 A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 be… Digital Experience Platform 7.2 / 7.4.3.25+ Fix from $1,6002022-10-18 MEDIUM 5.4 CVE-2022-42114 A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.… Dxp 7.4 / 7.4.3.37+ Fix from $1,6002022-10-18 MEDIUM 5.4 CVE-2022-42115 Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote att… Liferay Portal 7.4.3.37+ Fix from $1,6002022-10-18 MEDIUM 5.4 CVE-2022-38902 A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows … Dxp after 7.4.0 Fix from $1,6002022-10-13 MEDIUM 5.3 CVE-2022-41414 An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site … Liferay Portal after 7.4.2 Fix from $1,6002022-10-07 HIGH 7.5 CVE-2022-28981 Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside… Liferay Portal after 7.4.2 Fix from $1,9502022-09-22 MEDIUM 6.5 CVE-2022-38512 The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allow… Dxp after 7.4.3.36 Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-28980 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scri… Dxp 7.4.3.5+ Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-28977 HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack … Digital Experience Platform 7.4.3.4+ Fix from $1,6002022-09-22