Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in...
Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay DXP allow remote...
Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay DXP allows remote attackers to inject arbitrary...
This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal and Liferay DXP allows remote authenticated attackers to...
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user’s...
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted...
Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Calendar's “Name”...
Severity 2 Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the server,...
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the server, (3)...
Severity 2 Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the...
Liferay Portal 7.4.0 through 7.4.3.111 Liferay Portal 7.3.2 through 7.3.7 Liferay DXP 2023.Q4.0 through 2023.Q4.5 Liferay DXP 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 Liferay DXP 7.3 Liferay...
Liferay DXP 2023.Q3.6 This issue was reported by Erwin Krazek Severity 1 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal and Liferay DXP allows...
Severity 2 The Account Settings page in Liferay Portal and Liferay DXP embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed...
Liferay DXP 7.3 update 8 Liferay DXP 7.4 update 27 Liferay DXP 7.2 fix pack 20 This issue was reported by Barnabás Horváth (T4r0) Severity 2 User enumeration vulnerability in Liferay Portal and...
Workaround: Set the following in portal(-ext).properties: http.header.version.verbosity=partial Liferay DXP 7.2 fix pack 19 Severity 2 In Liferay Portal and Liferay DXP the default value of the...
This issue was reported by: Sompo Digital Lab Tel Aviv, Asaf Guterman Severity 2 Privilege escalation vulnerability in Wiki in Liferay Portal and Liferay DXP allows remote authenticated users to...
Severity 1 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload...
Severity 2 The Image Uploader module in Liferay Portal and Liferay DXP relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy