Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 2 In Liferay Portal and Liferay DXP, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML...
Severity 2 HtmlUtil.escapeRedirect in Liferay Portal and Liferay DXP can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via...
Liferay Portal 7.4.0 through 7.4.3.18 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.4 before update 19 Liferay DXP 7.3...
Liferay DXP 7.3 update 12 Liferay DXP 7.4 update 4 Liferay DXP 7.2 fix pack 20 Severity 2 XXE vulnerability in Liferay Portal and Liferay DXP allows attackers with permission to deploy...
Liferay DXP 7.2 fix pack 17 Severity 2 The Journal module in Liferay Portal and Liferay DXP grants guest users view permission to web content templates by default, which allows remote attackers to...
Severity 2 Liferay Portal and Liferay DXP does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User...
Severity 2 Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML...
Severity 1 Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML...
Liferay DXP 7.3 update 34 Liferay DXP 2023.Q3.6 This issue was reported by Amin ACHOUR Severity 1 Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay...
Liferay DXP 2023.Q3.6 This issue was reported by Amin ACHOUR Severity 2 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal and Liferay DXP allows remote...
Severity 2 Open redirect vulnerability in adaptive media administration page in Liferay DXP allows remote attackers to redirect users to arbitrary external URLs via the...
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web script or HTML via...
Severity 1 Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the filename of an...
Liferay Portal 7.4.0 through 7.4.2 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.3 before service pack 3 Liferay DXP 7.2...
Liferay DXP 7.3 update 4 Liferay Portal 7.4.3.4 Liferay DXP 7.2 fix pack 19 This issue was reported by Sahil Mehra Information disclosure vulnerability in the Control Panel in Liferay Portal and...
Severity 2 Liferay Portal and Liferay DXP does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote...
Liferay Portal 7.4.0 and 7.4.1 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.3 before service pack 3 Liferay DXP 7.2...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy