Vulnerability index

Browse CVEs

278 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-28979 Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to … Digital Experience Platform 7.4.3.4+ Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-28982 A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to exe… Dxp 7.4.3.4+ Fix from $1,6002022-09-22 MEDIUM 5.4 CVE-2022-28978 Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and L… Digital Experience Platform 7.4.2+ Fix from $1,6002022-09-22 MEDIUM 6.1 CVE-2022-26596 Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Lifera… Digital Experience Platform after 7.3.3 Fix from $1,6002022-04-25 MEDIUM 6.1 CVE-2022-26597 Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 bef… Digital Experience Platform 7.3+ Fix from $1,6002022-04-25 MEDIUM 5.4 CVE-2022-26593 Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 b… Digital Experience Platform 7.3 / 7.3.7+ Fix from $1,6002022-04-19 MEDIUM 6.1 CVE-2022-26594 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote att… Liferay Portal 7.3.7+ Fix from $1,6002022-04-15 MEDIUM 5.4 CVE-2021-38265 Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web scr… Digital Experience Platform after 7.3.6 Fix from $1,6002022-03-03 MEDIUM 5.4 CVE-2021-38267 Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before… Digital Experience Platform 7.3+ Fix from $1,6002022-03-03 MEDIUM 5.4 CVE-2021-38269 Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pac… Liferay Portal after 7.3.6 Fix from $1,6002022-03-03 MEDIUM 5.3 CVE-2022-25146 The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of … Digital Experience Platform 7.4.3.9+ Fix from $1,6002022-03-03 MEDIUM 6.1 CVE-2021-38263 Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pa… Liferay Portal after 7.3.2 Fix from $1,6002022-03-03 MEDIUM 6.1 CVE-2021-38264 Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary … Liferay Portal Patch available Fix from $1,6002022-03-03 HIGH 7.5 CVE-2021-38266 The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pac… Liferay Portal after 7.2.1 Fix from $1,9502022-03-02 MEDIUM 6.5 CVE-2021-38268 The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fi… Digital Experience Platform 7.2.1 / 7.3.7+ Fix from $1,6002022-03-02 HIGH 7.2 CVE-2020-28884 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute a… Liferay Portal Mitigation only Fix from $1,9502022-01-28 HIGH 7.2 CVE-2020-28885 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo … Liferay Portal Mitigation only Fix from $1,9502022-01-28 HIGH 7.5 CVE-2021-33338 The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in… Digital Experience Platform after 7.3.2 Fix from $1,9502021-08-04 MEDIUM 6.1 CVE-2021-33337 Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.… Digital Experience Platform after 7.3.4 Fix from $1,6002021-08-04 MEDIUM 6.1 CVE-2021-35463 Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script… Liferay Portal Mitigation only Fix from $1,6002021-08-04 MEDIUM 5.4 CVE-2021-33336 Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack… Digital Experience Platform 7.3.4+ Fix from $1,6002021-08-04 HIGH 7.2 CVE-2021-33335 Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows re… Digital Experience Platform 7.3.5+ Fix from $1,9502021-08-03 MEDIUM 6.3 CVE-2021-33333 The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pac… Digital Experience Platform 7.3.3+ Fix from $1,6002021-08-03 MEDIUM 6.1 CVE-2021-33331 Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix… Digital Experience Platform 7.3.2+ Fix from $1,6002021-08-03 MEDIUM 6.1 CVE-2021-33332 Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pa… Digital Experience Platform 7.3.3+ Fix from $1,6002021-08-03 HIGH 7.5 CVE-2021-33321 Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email add… Dxp 7.3 / 7.3.3+ Fix from $1,9502021-08-03 HIGH 7.5 CVE-2021-33322 In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens… Digital Experience Platform 7.3.1+ Fix from $1,9502021-08-03 HIGH 7.5 CVE-2021-33323 The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves f… Digital Experience Platform 7.3.1+ Fix from $1,9502021-08-03 MEDIUM 6.1 CVE-2021-33326 Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 b… Digital Experience Platform 7.3.5+ Fix from $1,6002021-08-03 MEDIUM 5.4 CVE-2021-33328 Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before… Digital Experience Platform 7.3.5+ Fix from $1,6002021-08-03