Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
-
Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 2025.Q1.0 through 2025.Q1.3 Liferay DXP 2024.Q4.0 through 2024.Q4.7 Liferay DXP 2024.Q3.1 through 2024.Q3.13 Liferay DXP 2024.Q2.0 throguh...
-
Liferay DXP 2025.Q1.4 Liferay DXP 2024.Q1.15 Liferay DXP 2025.Q2.0 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote authenticated attacker...
-
Liferay Portal and Liferay DXP allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs. Liferay Portal 7.4.0 through 7.4.3.131 Liferay...
-
Liferay Portal 7.4.3.132 Liferay DXP 2024.Q1.13 Liferay DXP 2024.Q3.10 Liferay DXP 2024.Q4.0 Liferay DXP 2025.Q1.0 Liferay Portal 7.4.3.86 through 7.4.3.131 Liferay DXP 2024.Q3.1 through 2024.Q3.9...
-
The Liferay Portal and Liferay DXP allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers....
-
A Stored cross-site scripting vulnerability in the Liferay Portal and Liferay DXP allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content. Liferay...
-
Liferay Portal 7.4.0 through 7.4.3.131 Liferay DXP 2024.Q4.0 through 2024.Q4.1 Liferay DXP 2024.Q3.1 through 2024.Q3.13 Liferay DXP 2024.Q2.0 throguh 2024.Q2.13 Liferay DXP 2024.Q1.1 through...
-
Liferay DXP 2025.Q1.0 Liferay DXP 2024.Q1.15 Liferay DXP 2025.Q2.0 Username enumeration vulnerability in Liferay Portal and Liferay DXP allows attackers to determine if an account exist in the...
-
Liferay Portal 7.4.0 through 7.4.3.131 Liferay DXP 2024.Q4.0 through 2024.Q4.3 Liferay DXP 2024.Q3.1 through 2024.Q3.12 Liferay DXP 2024.Q2.0 through 2024.Q2.13 Liferay DXP 2024.Q1.1 through...
-
User enumeration vulnerability in Liferay Portal and Liferay DXP allows remote attackers to determine if an account exist in the application via the create account page. Liferay Portal 7.4.0...
-
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal and Liferay DXP allows an remote non-authenticated attacker to inject JavaScript into the google_gadget. Liferay Portal...
-
Liferay Portal 7.4.3.132 Liferay Portal 7.4.3.132 Liferay DXP 2024.Q1.13 Liferay DXP 2024.Q4.5 Liferay DXP 2025.Q1.0 Liferay DXP 2024.Q4.5 Liferay DXP 2024.Q1.13 Liferay DXP 2025.Q1.0 A reflected...
-
The fragment preview functionality in Liferay Portal and Liferay DXP was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript...
-
Liferay Portal fixed on master branch Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.1 Liferay DXP 2024.Q1.15 Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 2025.Q1.0 Liferay DXP 2024.Q4.0 through...
-
Liferay DXP 2025.Q2.0 Liferay Portal fixed on master branch Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.2 Liferay DXP 2024.Q1.15 Liferay DXP 2024.Q1.15 Liferay DXP 2025.Q1.2 Liferay Portal and...
-
Liferay Portal and Liferay DXP allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allowing an attacker to cause a potential DDoS....
-
Liferay Portal fixed on master branch Liferay DXP 2025.Q2.0 Liferay DXP 2025.Q1.2 Liferay DXP 2024.Q1.15 Liferay Portal 7.4.0 through 7.4.3.132 Liferay DXP 2025.Q1.0 through 2025.Q1.1 Liferay DXP...
-
Liferay DXP 2024.Q3.1 Liferay DXP 2024.Q4.0 Liferay DXP 2024.Q1.13 The data exposure vulnerability in Liferay Portal and Liferay DXP allows an unauthorized user to obtain entry data from forms....
-
Liferay DXP 2024.Q3.1 Liferay DXP 2024.Q1.13 Liferay DXP 2024.Q4.0 Dtro and TF1T of VietSunshine Cyber Security Services Cross-site scripting (XSS) vulnerability on Liferay Portal and Liferay DXP...
-
Liferay DXP 2024.Q4.0 Enumeration of ERC from object entry in Liferay Portal and Liferay DXP allow attackers to determine existent ERC in the application by exploit the time response. Liferay...
-
This issue was reported by milCERT AT and Lucas Machado from Devoteam Cyber Trust A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal...
-
Stored cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to execute arbitrary web script or HTML via components tab. Liferay Portal 7.4.0 through...
-
Stored cross-site scripting (XSS) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via remote app title field. Liferay Portal 7.4.0...
-
Liferay Portal 7.4.0 through 7.4.3.38 Liferay DXP 7.4 GA through Update 38 Liferay Portal 7.4.3.39 Liferay Portal 7.4.3.39 Liferay DXP 7.4 Update 39 Liferay DXP 7.4 Update 39 This issue was...
-
Liferay DXP 2024.Q1.1 Liferay Portal 7.4.3.112 Liferay DXP 2023.Q3.5 Liferay DXP 2023.Q4.1 Liferay DXP 7.3 U36 This issue was reported by 4rth4s Liferay Portal and Liferay DXP does not limit access...
-
The Profile widget in Liferay Portal and Liferay DXP uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file...
-
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal and Liferay DXP allows remote attackers to view contact information, including the contact’s...
-
Liferay DXP 2023.Q3.9 Liferay DXP 2023.Q4.6 Liferay DXP 7.3 update 36 This issue was reported by foobar7 Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal and Liferay DXP...
-
Liferay Portal 7.4.3.112 Liferay Portal 7.4.3.112 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.6 Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 This issue was reported by foobar7 Multiple cross-site...
-
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload...
-
Liferay Portal 7.3.1 through 7.4.3.111 Liferay DXP 2023.Q4.0 through 2023.Q4.5 Liferay DXP 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 Liferay DXP 7.3 Liferay Portal 7.4.3.112 Liferay Portal...
-
Liferay DXP 2023.Q4.6 This issue was reported by foobar7 Cross-site request forgery (CSRF) vulnerability in Liferay Portal and Liferay DXP allows remote attackers to add and edit publication...
-
Liferay Portal 7.4.0 through 7.4.3.112 Liferay DXP 2023.Q4.0 through 2023.Q4.8 Liferay DXP 2023.Q3.1 through 2023.Q3.10 Liferay DXP 7.4 Liferay Portal 7.4.3.113 Liferay Portal 7.4.3.113 Liferay DXP...
-
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP allows remote authenticated users to from one virtual instance to view the shipment addresses of...Releases: Liferay DXP 2023.Q4
-
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal and Liferay DXP allows remote authenticated users to from one virtual instance to view the audit events...
-
Liferay DXP 2024.Q1.3 Liferay DXP 2024.Q2.0 Liferay DXP 2023.Q4.9 This issue was reported by argon21 Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal...
-
Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote authenticated users to inject...
-
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and Liferay DXP allows remote authenticated users in one virtual instance to assign an organization to a user in a different...
-
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted <iframe> injected into a...
-
This issue was reported by argon21 Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
Found a Security Vulnerability?
There's a different process available if you have a security issue to report...
Hall of Fame!
Raise your profile - report security vulnerabilities and enter the Hall of Fame!
Community
Company
Feedback