Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Liferay DXP 7.3 service pack 3 Liferay Portal 7.4.2 Liferay DXP 7.2 fix pack 15 Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal and Liferay DXP allows remote...
Severity 2 Liferay Portal and Liferay DXP returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote...
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary...
Severity 2 The IFrame widget in Liferay Portal and Liferay DXP does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self...
The Document and Media widget In Liferay Portal and Liferay DXP, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of...
Severity 2 A Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay DXP and Liferay Portal allows remote attackers to accept the site's terms of use via social...
Severity 2 Account lockout in Liferay Portal and Liferay DXP does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been...
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title`...
Severity 1 Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via...
Liferay Portal 7.4.3.92 This issue was reported by Michael Oelke Severity 1 Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal and Liferay DXP allow...
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML into a parent wiki...
Severity 2 Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a...
Severity 2 The organization selector in Liferay Portal and Liferay DXP does not check user permission, which allows remote authenticated users to obtain a list of all organizations. Liferay DXP 7.4...
Liferay Portal 7.4.3.77 This issue was reported by NDIx Severity 2 Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal and Liferay DXP allows remote attackers to...
Severity 2 Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy