Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
This issue was reported by milCERT AT and Lucas Machado from Devoteam Cyber Trust A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal...
Stored cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to execute arbitrary web script or HTML via components tab. Liferay Portal 7.4.0 through...
Stored cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via remote app title field. Liferay Portal 7.4.0...
Liferay Portal 7.4.0 through 7.4.3.38 Liferay DXP 7.4 GA through Update 38 Liferay Portal 7.4.3.39 Liferay Portal 7.4.3.39 Liferay DXP 7.4 Update 39 Liferay DXP 7.4 Update 39 This issue was...
Liferay DXP 2024.Q1.1 Liferay Portal 7.4.3.112 Liferay DXP 2023.Q3.5 Liferay DXP 2023.Q4.1 Liferay DXP 7.3 U36 This issue was reported by 4rth4s Liferay Portal and Liferay DXP does not limit access...
The Profile widget in Liferay Portal and Liferay DXP uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file...
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal and Liferay DXP allows remote attackers to view contact information, including the contact’s...
Liferay DXP 2023.Q3.9 Liferay DXP 2023.Q4.6 Liferay DXP 7.3 update 36 This issue was reported by foobar7 Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal and Liferay DXP...
Liferay Portal 7.4.3.112 Liferay Portal 7.4.3.112 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.6 Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 This issue was reported by foobar7 Multiple cross-site...
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload...
Liferay Portal 7.3.1 through 7.4.3.111 Liferay DXP 2023.Q4.0 through 2023.Q4.5 Liferay DXP 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 Liferay DXP 7.3 Liferay Portal 7.4.3.112 Liferay Portal...
Liferay DXP 2023.Q4.6 This issue was reported by foobar7 Cross-site request forgery (CSRF) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to add and edit publication...
Liferay Portal 7.4.0 through 7.4.3.112 Liferay DXP 2023.Q4.0 through 2023.Q4.8 Liferay DXP 2023.Q3.1 through 2023.Q3.10 Liferay DXP 7.4 Liferay Portal 7.4.3.113 Liferay Portal 7.4.3.113 Liferay DXP...
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP allows remote authenticated users to from one virtual instance to view the shipment addresses of...
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal and Liferay DXP allows remote authenticated users to from one virtual instance to view the audit events...
Liferay DXP 2024.Q1.3 Liferay DXP 2024.Q2.0 Liferay DXP 2023.Q4.9 This issue was reported by argon21 Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal...
Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote authenticated users to inject...
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and Liferay DXP allows remote authenticated users in one virtual instance to assign an organization to a user in a different...
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted <iframe> injected into a...
This issue was reported by argon21 Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy