Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
-
The Commerce component in Liferay Portal and Liferay DXP saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download...
-
Open redirect vulnerability in the System Settings in Liferay Portal and Liferay DXP allows remote attackers to redirect users to arbitrary external URLs via the...
-
This issue was reported by milCERT AT and Abderrahmane BOUNHIDJA Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal and Liferay DXP allows remote...
-
Open redirect vulnerability in page administration in Liferay Portal and Liferay DXP allows remote attackers to redirect users to arbitrary external URLs via the...
-
Liferay Portal and Liferay DXP does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex...
-
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal and Liferay DXP allows remote attackers to access arbitrary CSS and JSS files and load the files...
-
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1)...
-
Liferay Portal 7.4.3.22 Liferay DXP 7.4 Update 10 Liferay DXP 7.3 Update 26 Liferay Portal 7.0.0 through 7.4.3.21 Liferay DXP 7.4 GA through Update 9 Liferay DXP 7.3 GA through Update 25 Liferay...
-
Liferay DXP 7.3 update 28 Liferay DXP 7.4 update 1 Kaleo Forms Admin in Liferay Portal and Liferay DXP does not restrict the saving of request parameters in the portlet session, which allows...Releases: Liferay Portal 7.4 Liferay DXP 7.3 Liferay DXP 7.4
-
In Liferay Portal and Liferay DXP (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users. This allows remote...
-
Insufficient CSRF protection for omni-administrator users in Liferay Portal and Liferay DXP allows attackers to execute Cross-Site Request Forgery Liferay Portal 7.0.0 through 7.4.3.119 Liferay DXP...
-
Severity 1 Liferay Portal 7.4.3.102 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.0 Liferay DXP 2023.Q3.5 Liferay DXP 7.3 Update 36 Liferay Portal 7.4.0 through 7.4.3.101 Liferay Portal 7.3.0 through...
-
Liferay Portal and Liferay DXP does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API. Liferay DXP 2023.Q3.1...
-
Liferay Portal 7.4.3.110 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.1 Liferay DXP 2023.Q3.5 Liferay DXP 7.3 Update 36 Liferay DXP 2023.Q3.1 through 2023.Q3.4 Liferay DXP 7.4 Update 51 through Update...
-
Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal and Liferay DXP allows remote authenticated users to from one account to view addresses from a...
-
This issue was reported by foobar7 Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal and Liferay DXP allows remote authenticated attackers to view publication...
-
Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload...
-
Liferay Portal 7.4.3.21 through 7.4.3.111 Liferay DXP 2023.Q4.0 through 2023.Q4.5 Liferay DXP 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 Update 21 through Update 92 Liferay Portal 7.4.3.112...
-
Liferay Portal 7.4.3.112 Liferay Portal 7.4.3.112 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q4.6 Liferay DXP 2023.Q3.9 Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.9 This issue was...
-
Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected...
-
Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in...
-
Liferay DXP 2023.Q4.6 Liferay DXP 2024.Q1.1 Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay DXP allow remote...
-
Liferay DXP 2023.Q3.9 This issue was reported by foobar7 Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay DXP allows remote attackers to inject arbitrary...
-
This issue was reported by foobar7 Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal and Liferay DXP allows remote authenticated attackers to...
-
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user’s...
-
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay DXP allow remote attackers to inject arbitrary web script or HTML via a crafted...
-
Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Calendar's “Name”...
-
Severity 2 Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the server,...
-
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the server, (3)...
-
Severity 2 Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the...
-
Liferay Portal 7.4.3.102 through 7.4.3.110 Liferay DXP 2023.Q4.0 through 2023.Q4.2 Liferay DXP 2023.Q3.5 Liferay Portal 7.4.3.111 Liferay Portal 7.4.3.111 Liferay DXP 2024.Q1.1 Liferay DXP...
-
Liferay Portal 7.4.0 through 7.4.3.111 Liferay Portal 7.3.2 through 7.3.7 Liferay DXP 2023.Q4.0 through 2023.Q4.5 Liferay DXP 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 Liferay DXP 7.3 Liferay...
-
Liferay DXP 2023.Q3.6 This issue was reported by Erwin Krazek Severity 1 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal and Liferay DXP allows...
-
Severity 2 The Account Settings page in Liferay Portal and Liferay DXP embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed...
-
Liferay Portal 7.4.3.38 Liferay Portal 7.4.3.38 Liferay DXP 7.4 update 38 Liferay DXP 7.3 update 11 Liferay DXP 7.2 fix pack 20 Liferay DXP 7.3 update 11 Liferay DXP 7.4 update 38 Liferay DXP 7.2...
-
Liferay DXP 7.3 update 8 Liferay DXP 7.4 update 27 Liferay DXP 7.2 fix pack 20 This issue was reported by Barnabás Horváth (T4r0) Severity 2 User enumeration vulnerability in Liferay Portal and...
-
Workaround: Set the following in portal(-ext).properties: http.header.version.verbosity=partial Liferay DXP 7.2 fix pack 19 Severity 2 In Liferay Portal and Liferay DXP the default value of the...
-
This issue was reported by: Sompo Digital Lab Tel Aviv, Asaf Guterman Severity 2 Privilege escalation vulnerability in Wiki in Liferay Portal and Liferay DXP allows remote authenticated users to...
-
Severity 1 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and Liferay DXP allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload...
-
Severity 2 The Image Uploader module in Liferay Portal and Liferay DXP relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
Found a Security Vulnerability?
There's a different process available if you have a security issue to report...
Hall of Fame!
Raise your profile - report security vulnerabilities and enter the Hall of Fame!
Community
Company
Feedback