Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
By default, Liferay Portal and Liferay DXP is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary external URLs. This vulnerability can be mitigated by...
Password enumeration vulnerability in Liferay Portal and Liferay DXP allows remote attackers to determine a user’s password even if account lockout is enabled via brute force attack. Liferay...
Missing Authorization in Collection Provider component in the Liferay Portal and Liferay DXP allows instance users to read and select unauthorized Blueprints through the Collection Providers across...
A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal and Liferay DXP allows a remote, authenticated attacker to inject and...
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote non-authenticated attacker to inject JavaScript into the google_gadget. Liferay Portal...
Liferay DXP 2024.Q4.6 Liferay DXP 2024.Q1.13 Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.5 A vulnerability in Liferay Portal and Liferay DXP allows sensitive user data to be included in the...
A memory leak in the headless API for StructuredContents in Liferay Portal and Liferay DXP allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API...
Liferay Portal and Liferay DXP may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that share the same TLD to read...
A Stored cross-site scripting vulnerability in the Liferay Portal and Liferay DXP allows an remote authenticated attacker to inject JavaScript through the organization site names. The malicious...
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor...
Improper Access Control vulnerability in Liferay Portal and Liferay DXP allows guest users to obtain object entries information via the API Builder. Liferay Portal 7.4.3.125 Liferay DXP 2024.Q1.13...
Liferay Portal 7.4.3.45 through 7.4.3.125 Liferay DXP 7.4 U45 through U92 Liferay DXP 2024.Q1.1 through 2024.Q1.12 Liferay DXP 2024.Q2.0 through 2024.Q2.9 Liferay Portal 7.4.3.129 Liferay Portal...
Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 7.4 GA through U92 Liferay DXP 2024.Q1.1 through DXP 2024.Q1.19 Liferay DXP 2024.Q2.0 through DXP 2024.Q2.13 Liferay DXP 2024.Q3.0 through DXP...
Liferay DXP 2025.Q1.17 Liferay DXP 2024.Q1.20 Liferay DXP 2025.Q2.10 Liferay Portal and Liferay DXP exposes "Internal Server Error" in the response body when a login attempt is made with a deleted...
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal and Liferay DXP that affects custom object attachment fields. This flaw allows an attacker to manipulate the...
Liferay Portal and Liferay DXP has a security vulnerability that allowing for improper access through the expandoTableLocalService. Liferay Portal fixed on master branch Liferay DXP 2025.Q2.1...
Liferay Portal and Liferay DXP allows unauthenticated users with valid credentials to bypass the login process by changing the POST method to GET, once the site has MFA enabled. Liferay Portal...
Liferay Portal fixed on master branch Liferay DXP 2025.Q2.6 Liferay DXP 2025.Q1.16 Liferay DXP 2024.Q1.21 Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 2025.Q2.0 through 2025.Q2.5 Liferay DXP...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy