Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 2 Multiple permission issue exists in Liferay Portal 7.1 CE GA1 which allows users to perform actions on resources which they are not authorized to perform. Liferay Portal 7.1.1 Liferay...
Severity 2 In Liferay Portal 7.1 CE GA1, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML into a page. Liferay Portal 7.1.1 Liferay...
An open redirect vulnerability exits with Blogs RSS and tunnel-web in Liferay Portal 7.1 CE GA1. Severity 2 Liferay Portal 7.1.1 Liferay Portal 7.1.1 This issue was reported by Tiago Sintra
Liferay Portal 7.1.1 Liferay Portal 7.1.1 This issue was reported by Osama Mahmood Severity 2 In Liferay Portal 7.1 CE GA1, other sessions are not terminated when a user changes their password.
In LIferay Portal 7.0 CE GA7, a theoretical OS command injection vulnerability exists in SendmailHook. Severity 2 Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) By default, the...
Severity 2 The CSV files that are exported by Liferay Portal 7.0 CE GA7 (user export, DDL export and Form export) is susceptible to CSV injection if the CSV file is opened by some spreadsheet...
Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) Liferay Portal 7.1.0 In Liferay Portal 7.0 CE GA7, A cross-site request forgery (CSRF) vulnerability exist with comments. An attacker...
Severity 2 In Liferay Portal 7.0 CE GA7, the password for a Form's REST data provider does not obfuscate the password leading to password disclosure. Liferay Portal 7.1.0 Liferay Portal 7.1.0...
In Liferay Portal 7.0 CE GA7, a flaw in the code used to prevent open redirects allows some crafted URLs to circumvent the open redirect prevention logic. Severity 2 Liferay Portal 7.1.0...
Liferay Portal 7.1.0 Liferay Portal 7.1.0 7.0.6-ce-ga7-security-1.0 patch (source) Severity 2 In Liferay Portal 7.0 CE GA7, blogs titles are visible to users without the appropriate view...
Some vulnerabilities reported by Gergő Czuczor Severity 2 In Liferay Portal 7.0 CE GA7, multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or...
Multiple cross-site request forgery (CSRF) vulnerabilities allow remote attackers to execute unwanted actions in the portal. Workaround: Remove the following lines from the...
Severity 1 In Liferay Portal 7.0.5 and earlier, the Web Proxy portlet/application allows remote attackers to execute arbitrary code via supplied stylesheet. Patched versions of the portal will...
Liferay Portal 7.0.6 The portal may be vulnerable to BREACH attacks if the portal is using HTTPS and compression (GZip) is enabled. Workaround: Disable compression by setting...
Severity 2 The "doAsUserId" parameter used by Administrators for impersonating another user can be leaked to third party sites. Liferay Portal 7.0.6 Liferay Portal 7.0.6
The asset tag API leaks information about the user who created the asset tag. Severity 2 Liferay Portal 7.0.6 Liferay Portal 7.0.6
Liferay Portal 7.0.6 Liferay Portal 7.0.6 Severity 2 Multiple permission issue allows users to perform actions on resources which they are not authorized to perform.
A reflected cross-site scripting (XSS) vulnerability exist on the JSONWS API page. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page....
Severity 2 Apache Commons Email is vulnerable to SMTP header injection (CVE-2017-9801). Liferay Portal is not vulnerable, however, custom modules/apps using the Commons Email JAR bundled with the...
Liferay Portal 7.0.5 Liferay Portal 7.0.5 Severity 2 Content spoofing is possible via URL manipulation in applications that suppor tags. An attacker can potentially exploit this security...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy