threat
engine
.sh
Back
·
··:··
Home
/
Product
/
liferay portal
Product
liferay portal
321 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-62275
>= 7.4.0 and < 7.4.3.112
Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 202
5.3
MEDIUM
CVE-2025-62276
>= 7.4.0 and < 7.4.3.112
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and
5.5
MEDIUM
CVE-2025-62267
>= 7.4.3.35 and < 7.4.3.112
Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 t
6.1
MEDIUM
CVE-2025-62264
>= 7.4.3.8 and < 7.4.3.112
Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay
6.1
MEDIUM
CVE-2025-62265
>= 7.2.0 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported vers
5.4
MEDIUM
CVE-2025-62266
>= 7.4.0 and < 7.4.3.110
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2
6.1
MEDIUM
CVE-2025-62257
>= 7.4.0 and < 7.4.3.120
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024
5.3
MEDIUM
CVE-2025-62259
< 7.4.3.110
Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug
5.4
MEDIUM
CVE-2025-62258
>= 7.4.0 and < 7.4.3.108
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA
6.5
MEDIUM
CVE-2025-62261
>= 7.0.0 and < 7.4.3.100
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through
6.5
MEDIUM
CVE-2025-62260
>= 7.4.0 and < 7.4.3.99
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through updat
7.5
HIGH
CVE-2025-62262
>= 7.0.0 and < 7.4.3.98
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older uns
4.4
MEDIUM
CVE-2025-62263
>= 7.3.7 and < 7.4.3.104
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2
5.4
MEDIUM
CVE-2025-62253
<= 7.3.7
Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and L
6.1
MEDIUM
CVE-2025-62254
>= 7.4.0 and <= 7.4.3.111
The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023
7.5
HIGH
CVE-2025-62255
< 7.4.3.102
Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, a
6.1
MEDIUM
CVE-2025-62256
>= 7.4.0 and < 7.4.3.110
Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through u
5.3
MEDIUM
CVE-2025-62247
>= 7.4.0 and <= 7.4.3.132
Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th
6.5
MEDIUM
CVE-2025-62248
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 th
4.8
MEDIUM
CVE-2025-62249
>= 7.4.0 and < 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 thro
6.1
MEDIUM
CVE-2025-62250
>= 7.0.0 and < 7.4.3.132
Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023
6.5
MEDIUM
CVE-2025-62251
>= 7.3.0 and < 7.4.3.119
Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through u
6.5
MEDIUM
CVE-2025-62252
>= 7.1.0 and < 7.4.3.112
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, a
4.3
MEDIUM
CVE-2025-62246
>= 7.1.0 and < 7.4.3.112
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versio
5.4
MEDIUM
CVE-2025-62242
>= 7.4.1 and < 7.4.3.112
Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Life
4.3
MEDIUM
CVE-2025-62243
>= 7.4.1 and < 7.4.3.113
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2
5.4
MEDIUM
CVE-2025-62244
>= 7.3.1 and < 7.4.3.112
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2
4.3
MEDIUM
CVE-2025-62245
>= 7.4.1 and < 7.4.3.113
Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.
4.3
MEDIUM
CVE-2025-62239
>= 7.4.3.21 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP
5.4
MEDIUM
CVE-2025-62238
>= 7.4.3.21 and < 7.4.3.112
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.
5.4
MEDIUM
CVE-2025-62237
>= 7.4.3.8 and < 7.4.3.112
Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and L
5.4
MEDIUM
CVE-2025-62240
>= 7.4.3.35 and < 7.4.3.112
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay
5.4
MEDIUM
CVE-2025-43771
>= 7.4.3.102 and < 7.4.3.112
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and
5.4
MEDIUM
CVE-2025-43830
>= 7.3.2 and < 7.4.3.112
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro
6.1
MEDIUM
CVE-2025-43829
>= 7.4.3.18 and < 7.4.3.112
Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111,
5.4
MEDIUM
CVE-2025-43821
>= 7.4.0 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111
5.4
MEDIUM
CVE-2025-43822
>= 7.4.3.15 and < 7.4.3.112
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0
5.4
MEDIUM
CVE-2025-43823
>= 7.4.0 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Lifer
5.4
MEDIUM
CVE-2025-43824
< 7.4.3.112
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 20
5.4
MEDIUM
CVE-2025-43825
>= 7.4.0 and <= 7.4.3.132
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.
6.5
MEDIUM
CVE-2025-43826
>= 7.2.0 and < 7.4.3.113
Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older
5.4
MEDIUM
CVE-2025-43827
>= 7.2.0 and < 7.4.3.118
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsup
4.3
MEDIUM
CVE-2025-43817
>= 7.4.3.74 and < 7.4.3.112
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q
6.1
MEDIUM
CVE-2025-43813
>= 7.3.0 and <= 7.3.7
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and old
8.2
HIGH
CVE-2025-43812
>= 7.4.3.4 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023
5.4
MEDIUM
CVE-2025-43820
>= 7.4.3.35 and < 7.4.3.111
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.
5.4
MEDIUM
CVE-2025-43818
>= 7.4.3.35 and < 7.4.3.111
Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023
6.1
MEDIUM
CVE-2025-43815
>= 7.4.3.102 and < 7.4.3.111
Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, a
6.1
MEDIUM
CVE-2025-43811
>= 7.4.3.50 and < 7.4.3.112
Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.11
5.4
MEDIUM
CVE-2025-43816
< 7.4.3.120
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions
7.5
HIGH
CVE-2025-43819
>= 7.4.3.121 and < 7.4.3.132
A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 throu
6.5
MEDIUM
CVE-2025-43779
>= 7.4.0 and < 7.4.3.113
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 thro
6.1
MEDIUM
CVE-2025-43814
>= 7.2.0 and < 7.4.3.113
In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1
6.5
MEDIUM
CVE-2025-43810
>= 7.2.0 and < 7.4.3.113
Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Lif
4.3
MEDIUM
CVE-2025-43806
>= 7.2.0 and < 7.4.3.113
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10,
4.3
MEDIUM
CVE-2025-43807
>= 7.4.0 and < 7.4.3.113
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay
5.4
MEDIUM
CVE-2025-43808
>= 7.4.0 and < 7.4.3.113
The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2
5.3
MEDIUM
CVE-2025-43809
>= 7.4.0 and < 7.4.3.112
Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.11
4.3
MEDIUM
CVE-2025-43803
>= 7.4.0 and < 7.4.3.120
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and
4.3
MEDIUM
CVE-2025-43804
>= 7.4.3.93 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0,
6.1
MEDIUM
CVE-2025-43805
>= 7.3.0 and < 7.4.3.112
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3
5.3
MEDIUM
CVE-2025-43801
< 7.4.3.112
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versi
7.5
HIGH
CVE-2025-43802
>= 7.4.3.51 and < 7.4.3.110
Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51
6.1
MEDIUM
CVE-2025-43797
< 7.4.3.112
In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 G
5.4
MEDIUM
CVE-2025-43799
< 7.4.3.112
Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.
6.5
MEDIUM
CVE-2025-43800
>= 7.4.3.20 and < 7.4.3.112
Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.
6.1
MEDIUM
CVE-2025-43791
< 7.4.3.112
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.
6.1
MEDIUM
CVE-2025-43792
< 7.4.3.106
Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 thr
5.3
MEDIUM
CVE-2025-43793
< 7.4.3.106
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.
7.5
HIGH
CVE-2025-43794
< 7.4.3.112
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Lif
4.8
MEDIUM
CVE-2025-43796
>= 7.4.0 and < 7.4.3.102
Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though up
7.5
HIGH
CVE-2025-43795
>= 7.1.0 and < 7.4.3.102
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 20
6.1
MEDIUM
CVE-2025-43787
>= 7.4.0 and <= 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 t
5.4
MEDIUM
CVE-2025-43789
>= 7.4.0 and < 7.4.3.120
JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92
5.3
MEDIUM
CVE-2025-43788
>= 7.4.3.81 and <= 7.4.3.85
The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 8
4.3
MEDIUM
CVE-2025-43790
>= 7.4.0 and < 7.4.3.124
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through
8.1
HIGH
CVE-2025-43782
>= 7.4.0 and < 7.4.3.125
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through
4.3
MEDIUM
CVE-2025-43783
>= 7.4.0 and < 7.4.3.129
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through
6.1
MEDIUM
CVE-2025-43784
>= 7.4.0 and < 7.4.3.125
Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 202
6.5
MEDIUM
CVE-2025-43785
>= 7.4.3.45 and < 7.4.3.129
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 20
6.1
MEDIUM
CVE-2025-43786
>= 7.4.0 and < 7.4.3.129
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.
5.3
MEDIUM
CVE-2025-43781
>= 7.4.0 and < 7.4.3.129
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 throug
6.1
MEDIUM
CVE-2025-43775
>= 7.4.0 and < 7.4.3.129
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.
5.4
MEDIUM
CVE-2025-43776
>= 7.4.0 and <= 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025
5.4
MEDIUM
CVE-2025-43777
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 thro
5.3
MEDIUM
CVE-2025-43778
>= 7.4.0 and <= 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025
6.1
MEDIUM
CVE-2025-43763
>= 7.4.0 and < 7.4.3.132
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0
6.5
MEDIUM
CVE-2025-3586
>= 7.4.3.27 and < 7.4.3.43
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1
7.2
HIGH
CVE-2025-43773
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 202
9.1
CRITICAL
CVE-2025-43766
>= 7.4.0 and < 7.4.3.132
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13,
9.8
CRITICAL
CVE-2025-43765
>= 7.4.0 and < 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 th
6.1
MEDIUM
CVE-2025-43764
>= 7.4.0 and < 7.4.3.132
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Lifer
6.5
MEDIUM
CVE-2025-43767
>= 7.4.3.86 and < 7.4.3.132
Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Lifer
6.1
MEDIUM
CVE-2025-43769
>= 7.4.0 and < 7.4.3.132
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.
6.1
MEDIUM
CVE-2025-43768
>= 7.4.0 and < 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throu
7.7
HIGH
CVE-2025-43770
>= 7.4.0 and < 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 thro
6.1
MEDIUM
CVE-2025-43761
>= 7.4.0 and < 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 thro
6.1
MEDIUM
CVE-2025-43762
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
6.5
MEDIUM
CVE-2025-43759
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024
2.7
LOW
CVE-2025-43758
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
5.3
MEDIUM
CVE-2025-43760
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro
5.4
MEDIUM
CVE-2025-43751
>= 7.4.0 and <= 7.4.3.132
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 t
5.3
MEDIUM
CVE-2025-43752
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
6.5
MEDIUM
CVE-2025-43753
>= 7.4.3.32 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 t
5.4
MEDIUM
CVE-2025-43754
>= 7.4.0 and <= 7.4.3.132
Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3
5.3
MEDIUM
CVE-2025-43756
all versions
<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}--A reflected cross-site scripting (XSS) vulnerability in the
5.4
MEDIUM
CVE-2025-43755
>= 7.4.0 and <= 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0
5.4
MEDIUM
CVE-2025-43757
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 thro
5.4
MEDIUM
CVE-2025-43746
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 thro
5.4
MEDIUM
CVE-2025-43748
>= 7.0.0 and < 7.4.3.120
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 thr
6.8
MEDIUM
CVE-2025-43750
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
6.5
MEDIUM
CVE-2025-43749
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
5.3
MEDIUM
CVE-2025-43742
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro
6.1
MEDIUM
CVE-2025-43741
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro
5.4
MEDIUM
CVE-2025-43744
>= 7.4.0 and <= 7.4.3.132
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 t
5.4
MEDIUM
CVE-2025-43743
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
4.3
MEDIUM
CVE-2025-43745
>= 7.4.0 and <= 7.4.3.132
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 202
6.5
MEDIUM
CVE-2025-43737
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8
5.4
MEDIUM
CVE-2025-43738
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 thro
5.4
MEDIUM
CVE-2025-43739
>= 7.4.3.94 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
4.3
MEDIUM
CVE-2025-43740
>= 7.4.3.120 and <= 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2
5.4
MEDIUM
CVE-2025-43731
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro
5.4
MEDIUM
CVE-2025-43732
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throu
2.7
LOW
CVE-2025-43733
all versions
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7
5.4
MEDIUM
CVE-2025-43734
>= 7.4.0 and <= 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 thro
5.4
MEDIUM
CVE-2025-43735
>= 7.4.0 and <= 7.4.3.131
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 thro
6.1
MEDIUM
CVE-2025-43736
>= 7.4.3.0 and <= 7.4.3.132
A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0
4.3
MEDIUM
CVE-2025-4655
>= 7.4.0 and <= 7.4.3.132
SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5,
5.0
MEDIUM
CVE-2025-4581
>= 7.4.0 and <= 7.4.3.132
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throug
8.6
HIGH
CVE-2025-4576
>= 7.4.0 and <= 7.4.3.133
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 thro
6.1
MEDIUM
CVE-2025-4604
>= 7.4.3.80 and <= 7.4.3.132
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2
6.1
MEDIUM
CVE-2025-4599
>= 7.4.3.61 and < 7.4.3.132
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024
6.1
MEDIUM
CVE-2025-3594
>= 7.0.0 and <= 7.4.3.4
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay
9.8
CRITICAL
CVE-2025-3526
>= 7.0.0 and <= 7.4.3.21
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and old
7.5
HIGH
CVE-2025-3602
>= 7.4.0 and <= 7.4.3.97
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through updat
7.5
HIGH
CVE-2025-4388
>= 7.4.0 and < 7.4.3.132
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 thro
6.1
MEDIUM
CVE-2025-3760
>= 7.2.0 and <= 7.4.3.129
A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.
5.4
MEDIUM
CVE-2025-2565
>= 7.4.0 and <= 7.4.3.128
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12
4.3
MEDIUM
CVE-2025-2536
>= 7.4.3.82 and <= 7.4.3.128
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 throug
6.1
MEDIUM
CVE-2023-37940
>= 7.0.0 and < 7.4.3.88
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Life
4.8
MEDIUM
CVE-2024-11993
>= 7.1.0 and < 7.4.3.39
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update
6.1
MEDIUM
CVE-2024-8980
>= 7.0.0 and < 7.0.6
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 9
9.6
CRITICAL
CVE-2024-38002
>= 7.3.2 and <= 7.3.7
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2
9.0
CRITICAL
CVE-2024-26273
>= 7.4.0 and < 7.4.3.104
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay
8.8
HIGH
CVE-2024-26272
>= 7.3.2 and <= 7.3.7
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay
8.8
HIGH
CVE-2024-26271
>= 7.4.3.75 and < 7.4.3.112
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay
8.8
HIGH
CVE-2023-47795
>= 7.4.3.18 and < 7.4.3.102
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and
9.0
CRITICAL
CVE-2024-25151
>= 7.2.0 and < 7.4.3.4
The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack
5.4
MEDIUM
CVE-2024-26269
>= 7.2.0 and < 7.4.3.38
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Life
9.6
CRITICAL
CVE-2024-26266
>= 7.2.0 and < 7.4.3.14
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported version
9.0
CRITICAL
CVE-2024-25603
>= 7.2.0 and < 7.4.3.5
Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3
9.0
CRITICAL
CVE-2023-42498
>= 7.4.3.8 and < 7.4.3.98
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97
9.6
CRITICAL
CVE-2023-42496
>= 7.3.3 and < 7.4.3.98
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, a
9.6
CRITICAL
CVE-2023-40191
>= 7.4.3.44 and < 7.4.3.98
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.
9.0
CRITICAL
CVE-2024-25602
< 7.4.3.4
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and
9.0
CRITICAL
CVE-2024-25601
< 7.4.3.4
Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.
9.0
CRITICAL
CVE-2024-25152
< 7.4.3.4
Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupport
9.0
CRITICAL
CVE-2024-25147
< 7.4.2
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported ver
9.6
CRITICAL
CVE-2021-29038
<= 7.2.1
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17,
6.3
MEDIUM
CVE-2024-26270
>= 7.4.3.76 and < 7.4.3.100
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 t
6.5
MEDIUM
CVE-2024-26268
<= 7.3.7
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 befor
5.3
MEDIUM
CVE-2024-26267
<= 7.3.7
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update
5.3
MEDIUM
CVE-2024-26265
<= 7.3.7
The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before upd
5.0
MEDIUM
CVE-2024-25610
< 7.4.3.13
In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4
9.0
CRITICAL
CVE-2024-25609
< 7.4.3.13
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before updat
6.1
MEDIUM
CVE-2024-25608
< 7.4.3.19
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before updat
6.1
MEDIUM
CVE-2024-25607
<= 7.4.3.15
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions
8.1
HIGH
CVE-2024-25606
< 7.4.3.8
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.
8.0
HIGH
CVE-2024-25605
< 7.4.3.5
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before ser
5.3
MEDIUM
CVE-2024-25604
< 7.4.3.5
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 befor
6.5
MEDIUM
CVE-2024-25150
< 7.4.3.4
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, a
4.3
MEDIUM
CVE-2024-25149
< 7.4.2
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack
5.4
MEDIUM
CVE-2023-5190
>= 7.4.3.45 and < 7.4.3.102
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Lif
6.1
MEDIUM
CVE-2022-45320
< 7.4.3.16
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote
6.3
MEDIUM
CVE-2024-25148
>= 7.2.0 and <= 7.4.1
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix p
5.4
MEDIUM
CVE-2024-25146
>= 7.2.0 and <= 7.4.1
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack
5.3
MEDIUM
CVE-2024-25144
>= 7.2.0 and < 7.4.3.26
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27,
4.1
MEDIUM
CVE-2023-47798
>= 7.2.0 and < 7.3.0
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and
5.4
MEDIUM
CVE-2024-25145
<= 7.2.1
Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.
9.6
CRITICAL
CVE-2024-25143
< 7.2.0
The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before se
6.5
MEDIUM
CVE-2023-47797
>= 7.4.3.94 and <= 7.4.3.95
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 all
9.6
CRITICAL
CVE-2023-42627
>= 7.3.5 and < 7.4.3.92
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Li
9.6
CRITICAL
CVE-2023-42628
>= 7.1.0 and < 7.4.3.88
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 f
9.0
CRITICAL
CVE-2023-44311
>= 7.4.3.41 and < 7.4.3.90
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedire
9.6
CRITICAL
CVE-2023-44310
>= 7.3.6 and < 7.4.3.49
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix p
9.0
CRITICAL
CVE-2023-44309
>= 7.4.2 and < 7.4.3.53
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, an
9.0
CRITICAL
CVE-2023-42629
>= 7.4.2 and < 7.4.3.88
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Lifera
9.0
CRITICAL
CVE-2023-42497
>= 7.4.3.4 and < 7.4.3.86
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85,
9.6
CRITICAL
CVE-2023-3426
>= 7.4.3.81 and <= 7.4.3.85
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check use
4.3
MEDIUM
CVE-2023-35030
>= 7.4.3.70 and < 7.4.3.77
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.
8.8
HIGH
CVE-2023-3193
>= 7.4.3.70 and < 7.4.3.74
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and
6.1
MEDIUM
CVE-2023-35029
>= 7.4.3.70 and < 7.4.3.77
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP
6.1
MEDIUM
CVE-2023-33950
>= 7.4.3.48 and <= 7.4.3.76
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions
6.5
MEDIUM
CVE-2023-33949
>= 7.0.0 and <= 7.0.6
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify th
5.3
MEDIUM
CVE-2023-33948
all versions
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files
5.3
MEDIUM
CVE-2023-33947
>= 7.4.3.4 and <= 7.4.3.60
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definit
2.7
LOW
CVE-2023-33946
>= 7.4.3.4 and <= 7.4.3.48
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects i
2.7
LOW
CVE-2023-33945
>= 7.3.1 and <= 7.3.7
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 be
6.4
MEDIUM
CVE-2023-33944
>= 7.3.4 and <= 7.3.7
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before upd
4.8
MEDIUM
CVE-2023-33943
>= 7.4.3.21 and <= 7.4.3.62
Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 up
5.4
MEDIUM
CVE-2023-33942
all versions
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Portal 7.4.3.50,
5.4
MEDIUM
CVE-2023-33941
>= 7.4.3.41 and <= 7.4.3.52
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class i
6.1
MEDIUM
CVE-2023-33940
>= 7.4.0 and <= 7.4.3.30
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4
4.8
MEDIUM
CVE-2023-33939
>= 7.1.0 and <= 7.4.3.12
Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.
5.4
MEDIUM
CVE-2023-33938
>= 7.3.0 and <= 7.3.7
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.
4.8
MEDIUM
CVE-2023-33937
>= 7.1.0 and <= 7.3.0
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DX
5.4
MEDIUM
CVE-2021-33990
all versions
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor di
9.8
CRITICAL
CVE-2022-42132
>= 7.0.0 and < 7.4.3.5
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 befor
5.9
MEDIUM
CVE-2022-42131
>= 7.1.0 and < 7.4.3.4
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data provid
4.8
MEDIUM
CVE-2022-42130
>= 7.1.0 and < 7.4.3.5
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pa
4.3
MEDIUM
CVE-2022-42129
>= 7.3.2 and < 7.4.3.5
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.
4.3
MEDIUM
CVE-2022-42128
>= 7.4.1 and < 7.4.3.5
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permission
5.3
MEDIUM
CVE-2022-42127
>= 7.4.3.5 and < 7.4.3.37
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check
5.3
MEDIUM
CVE-2022-42126
>= 7.3.5 and < 7.4.3.29
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before updat
4.3
MEDIUM
CVE-2022-42125
>= 7.4.3.5 and < 7.4.3.36
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34
7.5
HIGH
CVE-2022-42124
>= 7.3.2 and < 7.4.3.5
ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack
7.5
HIGH
CVE-2022-42123
>= 7.3.3 and < 7.4.3.19
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before updat
7.5
HIGH
CVE-2022-42122
all versions
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4
9.8
CRITICAL
CVE-2022-42121
>= 7.1.3 and <= 7.4.3.4
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27
8.8
HIGH
CVE-2022-42120
>= 7.3.3 and <= 7.4.3.16
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4
9.8
CRITICAL
CVE-2022-42119
>= 7.3.5 and <= 7.4.2
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 t
5.4
MEDIUM
CVE-2022-42118
>= 7.1.0 and <= 7.4.2
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1
6.1
MEDIUM
CVE-2022-42111
>= 7.2.1 and <= 7.4.2
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Li
5.4
MEDIUM
CVE-2022-42110
>= 7.1.0 and <= 7.4.2
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1
6.1
MEDIUM
CVE-2022-38901
>= 7.3.5 and <= 7.4.3.28
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experie
5.4
MEDIUM
CVE-2022-42117
>= 7.3.2 and <= 7.4.3.16
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP
6.1
MEDIUM
CVE-2022-42116
>= 7.3.2 and < 7.4.3.15
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 throu
6.1
MEDIUM
CVE-2022-42115
>= 7.4.3.4 and < 7.4.3.37
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.3
5.4
MEDIUM
CVE-2022-42114
>= 7.4.0 and < 7.4.3.37
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36,
5.4
MEDIUM
CVE-2022-42113
>= 7.4.3.30 and < 7.4.3.37
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP
6.1
MEDIUM
CVE-2022-42112
>= 7.2.0 and < 7.4.3.25
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and
5.4
MEDIUM
CVE-2022-38902
>= 7.3.0 and <= 7.4.0
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform
5.4
MEDIUM
CVE-2022-41414
>= 7.0.0 and <= 7.4.2
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumera
5.3
MEDIUM
CVE-2022-38512
>= 7.4.3.12 and <= 7.4.3.36
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permi
6.5
MEDIUM
CVE-2022-28981
>= 7.4.0 and <= 7.4.2
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to a
7.5
HIGH
CVE-2022-28980
< 7.4.3.5
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute
6.1
MEDIUM
CVE-2022-28977
>= 7.3.1 and < 7.4.3.4
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 throug
6.1
MEDIUM
CVE-2022-39975
>= 7.3.3 and < 7.4.3.35
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does
4.3
MEDIUM
CVE-2022-28982
>= 7.3.3 and < 7.4.3.4
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allo
6.1
MEDIUM
CVE-2022-28979
>= 7.1.0 and < 7.4.3.4
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3
6.1
MEDIUM
CVE-2022-28978
>= 7.0.1 and < 7.4.2
Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 t
5.4
MEDIUM
CVE-2022-26597
>= 7.3.0 and <= 7.4.0
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and
6.1
MEDIUM
CVE-2022-26596
>= 7.1.0 and <= 7.3.3
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 throug
6.1
MEDIUM
CVE-2022-26595
all versions
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permissio
4.3
MEDIUM
CVE-2022-26593
>= 7.3.3 and < 7.3.7
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, an
5.4
MEDIUM
CVE-2022-26594
>= 7.3.5 and < 7.3.7
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack
6.1
MEDIUM
CVE-2022-25146
>= 7.4.3.4 and < 7.4.3.9
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not chec
5.3
MEDIUM
CVE-2021-38269
>= 7.1.0 and <= 7.3.6
Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP
5.4
MEDIUM
CVE-2021-38267
>= 7.3.2 and <= 7.3.6
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Lif
5.4
MEDIUM
CVE-2021-38265
>= 7.3.4 and <= 7.3.6
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to injec
5.4
MEDIUM
CVE-2021-38264
all versions
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers t
6.1
MEDIUM
CVE-2021-38263
<= 7.3.2
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DX
6.1
MEDIUM
CVE-2021-38266
<= 7.2.1
The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and
7.5
HIGH
CVE-2021-38268
>= 7.0.0 and < 7.3.7
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pac
6.5
MEDIUM
CVE-2020-28885
all versions
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject command
7.2
HIGH
CVE-2020-28884
all versions
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy
7.2
HIGH
CVE-2021-35463
all versions
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject a
6.1
MEDIUM
CVE-2021-33338
>= 7.1.0 and <= 7.3.2
The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, expose
7.5
HIGH
CVE-2021-33337
>= 7.3.0 and <= 7.3.4
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4,
6.1
MEDIUM
CVE-2021-33339
>= 7.2.1 and < 7.3.5
Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before
4.8
MEDIUM
CVE-2021-33336
>= 7.3.0 and < 7.3.4
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Lifer
5.4
MEDIUM
CVE-2021-33335
>= 7.0.3 and < 7.3.5
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before f
7.2
HIGH
CVE-2021-33334
>= 7.0.0 and < 7.3.3
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack
4.3
MEDIUM
CVE-2021-33333
< 7.3.3
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and
6.3
MEDIUM
CVE-2021-33332
>= 7.1.0 and < 7.3.3
Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DX
6.1
MEDIUM
CVE-2021-33331
>= 7.0.0 and < 7.3.2
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack
6.1
MEDIUM
CVE-2021-33330
>= 7.2.0 and < 7.3.3
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) p
4.3
MEDIUM
CVE-2021-33328
>= 7.0.0 and < 7.3.5
Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Lif
5.4
MEDIUM
CVE-2021-33327
>= 7.2.0 and < 7.3.4
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack 93 and 94, 7.1 fix pack
4.3
MEDIUM
CVE-2021-33326
< 7.3.5
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before
6.1
MEDIUM
CVE-2021-33325
< 7.3.3
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, an
4.9
MEDIUM
CVE-2021-33324
>= 7.1.0 and < 7.3.2
The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does n
4.3
MEDIUM
CVE-2021-33323
>= 7.1.0 and < 7.3.1
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix
7.5
HIGH
CVE-2021-33322
< 7.3.1
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, pa
7.5
HIGH
CVE-2021-33321
>= 6.2.3 and < 7.3.3
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enume
7.5
HIGH
CVE-2021-33320
< 7.3.1
The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 befo
4.3
MEDIUM
CVE-2021-29052
>= 7.3.0 and <= 7.3.5
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in
4.3
MEDIUM
CVE-2021-29051
>= 7.2.0 and <= 7.3.5
Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Life
6.1
MEDIUM
CVE-2021-29048
all versions
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Lifera
6.1
MEDIUM
CVE-2021-29053
all versions
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated us
8.8
HIGH
CVE-2021-29046
all versions
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay D
6.1
MEDIUM
CVE-2021-29045
>= 7.3.2 and <= 7.3.5
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through
6.1
MEDIUM
CVE-2021-29044
>= 7.0.0 and <= 7.3.5
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 thro
6.1
MEDIUM
CVE-2021-29043
>= 7.0.0 and <= 7.3.5
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2
5.9
MEDIUM
CVE-2021-29047
all versions
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA
7.5
HIGH
CVE-2021-29040
<= 7.3.4
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2
5.3
MEDIUM
CVE-2021-29039
all versions
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remot
6.1
MEDIUM
CVE-2020-25476
all versions
Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name param
6.1
MEDIUM
CVE-2020-15840
< 7.3.1
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id
5.3
MEDIUM
CVE-2020-15839
< 7.3.3
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a mul
6.5
MEDIUM
CVE-2020-24554
< 7.3.3
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, wh
7.5
HIGH
CVE-2020-15842
< 7.3.0
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man
8.1
HIGH
CVE-2020-15841
< 7.3.0
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not s
8.3
HIGH
CVE-2020-13445
all versions
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the temp
8.8
HIGH
CVE-2020-13444
all versions
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does no
6.5
MEDIUM
CVE-2020-7961
< 7.2.1
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JS
9.8
CRITICAL
CVE-2020-7934
>= 7.1.0 and <= 7.2.1
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPort
5.4
MEDIUM
CVE-2019-16891
<= 6.0.6
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
9.8
CRITICAL
CVE-2019-16147
< 7.2.0
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
6.1
MEDIUM
CVE-2019-6588
<= 6.0.6
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized inpu
4.7
MEDIUM
CVE-2019-11444
all versions
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands
7.2
HIGH
CVE-2018-10795
<= 6.2.5
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types tha
8.8
HIGH
CVE-2017-1000425
< 7.0.3_ga4
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote a
6.1
MEDIUM
CVE-2017-17868
all versions
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_
6.1
MEDIUM
CVE-2017-12649
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
6.1
MEDIUM
CVE-2017-12648
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
6.1
MEDIUM
CVE-2017-12647
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
6.1
MEDIUM
CVE-2017-12646
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
6.1
MEDIUM
CVE-2017-12645
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
6.1
MEDIUM
CVE-2016-10404
<= 7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa
6.1
MEDIUM
CVE-2010-5327
<= 6.2.10
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity templat
8.8
HIGH
CVE-2016-3670
<= 6.2
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows re
6.1
MEDIUM
CVE-2014-8349
<= 6.2
Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated
CVE-2014-2963
all versions
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.
CVE-2011-1571
>= 5.1.0 and <= 5.1.2
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Ap
CVE-2011-1570
>= 6.0.0 and <= 6.0.5
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used,
CVE-2011-1504
all versions
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authen
CVE-2011-1503
>= 5.1.0 and <= 5.1.2
The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFi
CVE-2011-1502
>= 6.0.0 and <= 6.0.5
Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read a
CVE-2009-3742
<= 5.2.3
Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or
CVE-2007-6055
all versions
Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arb
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin