Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows a remote authenticated attacker to inject JavaScript code in the “first display label” field in the...
Liferay Portal fixed on master branch Liferay DXP 2025.Q2.0 Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 2025.Q1.0 through 2025.Q1.15 Liferay DXP 2024.Q4.0 through 2024.Q4.7 Liferay DXP...
Liferay DXP 2024.Q1.18 Liferay DXP 2025.Q1.11 Liferay Portal 7.4.3.132 Liferay Portal and Liferay DXP is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the...
Liferay DXP 2024.Q4.6 This issue was reported by Shubham Shah - CTO @ Assetnote and Adam Kues - Security Researcher @ Assetnote A reflected cross-site scripting (XSS) vulnerability in the Liferay...
A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal and Liferay DXP allows a user to upload more than 300kb profile picture into the user profile. This size more than the...
Liferay Portal fixed on master branch Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.8 Liferay DXP 2024.Q1.17 Liferay Portal 7.4.3.32 through 7.4.3.132 Liferay DXP 2025.Q1.0 through 2025.Q1.7 Liferay...
Liferay DXP 2024.Q1.17 Liferay DXP 2025.Q1.8 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows a remote authenticated attacker to inject JavaScript...
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote authenticated user to inject JavaScript in message board threads and categories. Liferay...
Liferay Portal and Liferay DXP allow any authenticated user to modify the content of emails sent through the calendar portlet, allowing an attacker to send phishing emails to any other user in the...
Liferay DXP 2024.Q3.0 Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and Liferay DXP allows remote authenticated users to from one virtual instance to access, create,...
JSON Web Services in Liferay Portal and Liferay DXP published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed. Liferay Portal 7.4.0 through...
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and Liferay DXP allows remote authenticated users to access a workflow definition by name via the API Liferay Portal 7.4.0...
This issue was reported by 4rth4s The organization selector in Liferay Portal and Liferay DXP does not check user permission, which allows remote authenticated users to obtain a list of all...
Liferay DXP 7.3 Update 35 Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal and Liferay DXP allows remote attackers to (1) add files to arbitrary...
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet Liferay Portal...
SSRF vulnerability in FreeMarker templates in Liferay Portal and Liferay DXP allows template editors to bypass access validations via crafted URLs. Liferay Portal 7.4.0 through 7.4.3.132 Liferay...
Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.6 Liferay Portal and Liferay DXP allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library...
Liferay Portal and Liferay DXP allows any authenticated remote user to view other calendars by allowing them to enumerate the names of other users, given an attacker the possibility to send...
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote non-authenticated attacker to inject JavaScript into the...
Liferay Portal and Liferay DXP allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validation of user-supplied URLs. An attacker...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy