Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
A memory leak in the headless API for StructuredContents in Liferay Portal and Liferay DXP allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API...
Liferay DXP 2024.Q2.0 Liferay Portal 7.4.3.113 Liferay DXP 2023.Q4.8 Liferay DXP 2024.Q1.1 Batch Engine in Liferay Portal and Liferay DXP does not properly check permission with import and export...
Liferay DXP 2023.Q3.9 Liferay DXP 2023.Q4.8 Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal and Liferay DXP allows remote attackers to...
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the...
Liferay Portal and Liferay DXP does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted...
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal and Liferay DXP allows remote attackers to perform a denial-of-service (DoS) attacks via a crafted XML-RPC request....
In Liferay Portal and Liferay DXP, the default membership type of a newly created site is “Open” which allows any registered users to become a member of the site. A remote attacker with site...
Liferay DXP allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user....
Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.5 Liferay DXP 2023.Q4.1 Liferay Portal 7.4.3.112 Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal and Liferay DXP allows remote...
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text"...
Remote staging in Liferay DXP does not properly obtain the remote address of the live site from the database which, which allows remote authenticated users to exfiltrate data to an attacker...
Liferay Portal and Liferay DXP may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that share the same TLD to read...
Liferay DXP 7.3 U36 Liferay DXP 2023.Q3.5 Liferay Portal and Liferay DXP does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform...
A Stored cross-site scripting vulnerability in the Liferay Portal and Liferay DXP allows an remote authenticated attacker to inject JavaScript through the organization site names. The malicious...
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor...
Improper Access Control vulnerability in Liferay Portal and Liferay DXP allows guest users to obtain object entries information via the API Builder. Liferay Portal 7.4.3.125 Liferay DXP 2024.Q1.13...
Liferay Portal 7.4.3.45 through 7.4.3.125 Liferay DXP 7.4 U45 through U92 Liferay DXP 2024.Q1.1 through 2024.Q1.12 Liferay DXP 2024.Q2.0 through 2024.Q2.9 Liferay Portal 7.4.3.129 Liferay Portal...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy