• Skip to Content

Known Vulnerabilities

This website uses cookies to ensure you get the best experience. Learn More.

Accept
  • Ask
  • Blogs
  • Chat
  • Download
  • Feedback
  • Help
  • Learn
  • Projects
  • /dev/24
  • Log In

Known Vulnerabilities

  • Overview
  • Reporting Security Issues
  • Known Vulnerabilities
  • Hall of Fame

Releases

  • Liferay Portal 7.4
  • Liferay Portal 7.3
  • Liferay Portal 7.2
  • Liferay Portal 7.1
  • Liferay Portal 7.0
  • Liferay Portal 6.2 CE
  • Liferay Faces
  • Liferay DXP 7.4
  • Liferay DXP 7.3
  • Liferay DXP 7.2
  • LIferay DXP 7.1
  • LIferay DXP 7.0
  • CVE-2023-3426 Unauthorized view access to Organization names

  • CVE-2023-3193 Reflected XSS with backURL in SEO configuration

  • CVE-2023-35029 Open redirect with backURL in SEO configuration

  • CVE-2023-35030 CSRF/RCE with backURL in SEO configuration

  • CVE-2023-33939 Stored XSS in Modified Facet

  • CVE-2023-33940 Stored XSS with IFrame type Remote App URL

  • CVE-2023-33941 Reflected XSS with 'code' and 'error' in OAuth2ProviderApplicationRedirect

  • CVE-2023-33942 Stored XSS with article title in Web Content Display widget

  • CVE-2023-33943 XSS with user name in account

  • CVE-2023-33944 XSS with container layout fragment URL

  • CVE-2023-33945 SQL injection in SQL Server upgrades

  • CVE-2023-33946 Unauthorized access to objects via OAuth 2 scope

  • CVE-2023-33947 Unauthorized access to object definition via search

  • CVE-2023-33948 Unauthorized access to Document and Media files via Forms

  • CVE-2023-33950 ReDoS vulnerability with Pattern Redirects

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.

  • Community
  • Ask
  • Events
  • Learn
  • Meet
  • Company
  • Blogs
  • Careers
  • Download
  • Open Source
  • Feedback
  • Contact Us

Copyright © 2023 Liferay, Inc

Powered by Liferay Portal CE™