Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Liferay Portal 7.3.7 Liferay Portal 7.3.7 Liferay Portal 7.4.1 August 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal...
Liferay Portal 7.2.1 Liferay Portal 7.2.1 In Liferay Portal 7.0.6, 7.1.3, 7.2.0, and possibly earlier unsupported versions, the MembershipRequestService APIs can be used in a denial-of-service...
Severity 2 Cross-site scripting (XSS) vulnerability in the Forms and Workflow module's edit workflow configuration in Liferay Portal 7.0.0 through 7.0.6 allows remote attackers to inject arbitrary...
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via...
Liferay Portal 7.3.6 Liferay Portal 7.3.6 Severity 2 Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 allow remote authenticated users to execute arbitrary SQL commands via the...
Severity 2 Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via...
The Portal Workflow module in Liferay Portal 6.2.2 through 7.3.2, user's passwords are stored in the database if workflow is enabled for new users. This allows attackers with access to the database...
Severity 2 Cross-site scripting (XSS) vulnerability in the portlet configuration module in Liferay Portal 7.1.0 through 7.3.2 allows remote attackers to inject arbitrary web script or HTML via the...
Liferay Portal 7.3.3 The Dynamic Data Mapping module in Liferay Portal 7.3.2 and earlier, do not properly check user permissions, which allows remote attackers with the forms "Access in Site...
Severity 2 The Layout module in Liferay Portal 6.2.0 through 6.2.5, 7.1.0 through 7.3.2 and earlier exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and...
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, allows remote attackers to enumerate user email addresses via the forgot password functionality. The portal.property...
Liferay Portal 7.3.1 Liferay Portal 7.3.1 May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. There is no fix...
Cross-site scripting (XSS) vulnerability in the layout module in Liferay Portal 7.2.0 and 7.2.1 allows remote attackers to inject arbitrary web script or HTML via the...
Cross-site scripting (XSS) vulnerability in the asset module in Liferay Portal 7.0.0 through 7.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1)...
Severity 2 Cross-site scripting (XSS) vulnerability in document library module in Liferay Portal 7.3.0 through 7.3.4 allow remote attackers to inject arbitrary web script or HTML via the...
Liferay Portal 7.3.5 Liferay Portal 7.3.5 May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. Severity 2...
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by...
Severity 2 Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the title of a...
Severity 2 Liferay Portal 7.3.4 May 2021 source patch for Liferay Portal 7.2.1. Details for working with source patches can be found on the Patching Liferay Portal page. Liferay Portal 7.3.4 The...
Severity 2 Cross-site scripting (XSS) vulnerability in Web Content Display in Liferay Portal 7.1.1 through 7.3.3 allows remote attackers to inject arbitrary web script or HTML via web content...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy