Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
-
Severity 2 In Liferay Portal and Liferay DXP, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML...
-
Severity 2 HtmlUtil.escapeRedirect in Liferay Portal and Liferay DXP can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via...
-
Liferay Portal 7.4.0 through 7.4.3.18 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.4 before update 19 Liferay DXP 7.3...
-
Liferay Portal 7.4.3.14 Liferay Portal 7.4.3.14 Liferay DXP 7.4 update 16 Liferay DXP 7.3 update 4 Liferay DXP 7.2 fix pack 17 Liferay DXP 7.3 update 4 Liferay DXP 7.4 update 16 Workaround: Set the...
-
Liferay DXP 7.3 update 12 Liferay DXP 7.4 update 4 Liferay DXP 7.2 fix pack 20 Severity 2 XXE vulnerability in Liferay Portal and Liferay DXP allows attackers with permission to deploy...
-
Liferay DXP 7.2 fix pack 17 Severity 2 The Journal module in Liferay Portal and Liferay DXP grants guest users view permission to web content templates by default, which allows remote attackers to...
-
Severity 2 Liferay Portal and Liferay DXP does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User...
-
Severity 2 Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML...
-
Severity 1 Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML...
-
Liferay DXP 7.3 update 34 Liferay DXP 2023.Q3.6 This issue was reported by Amin ACHOUR Severity 1 Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay...
-
Liferay DXP 2023.Q3.6 This issue was reported by Amin ACHOUR Severity 2 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal and Liferay DXP allows remote...
-
Severity 2 Open redirect vulnerability in adaptive media administration page in Liferay DXP allows remote attackers to redirect users to arbitrary external URLs via the...Releases: Liferay DXP 7.4 Liferay DXP 2023.Q3
-
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
-
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web script or HTML via...
-
Severity 1 Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary web...
-
Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the filename of an...
-
Liferay Portal 7.4.0 through 7.4.2 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.3 before service pack 3 Liferay DXP 7.2...
-
Liferay DXP 7.3 update 4 Liferay Portal 7.4.3.4 Liferay DXP 7.2 fix pack 19 This issue was reported by Sahil Mehra Information disclosure vulnerability in the Control Panel in Liferay Portal and...
-
Severity 2 Liferay Portal and Liferay DXP does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote...
-
Liferay Portal 7.4.0 and 7.4.1 Liferay Portal 7.3.0 through 7.3.7 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported versions Liferay DXP 7.3 before service pack 3 Liferay DXP 7.2...
-
Liferay DXP 7.3 service pack 3 Liferay Portal 7.4.2 Liferay DXP 7.2 fix pack 15 Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal and Liferay DXP allows remote...
-
Severity 2 Liferay Portal and Liferay DXP returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote...
-
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal and Liferay DXP allows remote authenticated users to inject arbitrary...
-
Severity 2 The IFrame widget in Liferay Portal and Liferay DXP does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self...
-
The Document and Media widget In Liferay Portal and Liferay DXP, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of...
-
Severity 2 A Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay DXP and Liferay Portal allows remote attackers to accept the site's terms of use via social...
-
Severity 2 Liferay Portal 7.3.6 Liferay DXP 7.3 service pack 1 Liferay DXP 7.2 fix pack 17 Liferay Portal 7.3.0 through 7.3.5 Liferay Portal 7.2.0 and 7.2.1 Liferay Portal, older unsupported...
-
Severity 2 Account lockout in Liferay Portal and Liferay DXP does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been...
-
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title`...Releases: Liferay DXP 7.4
-
Severity 1 Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Liferay DXP 7.4 update 41 through update 89 Liferay Portal 7.4.3.41 through 7.4.3.89 Liferay DXP 7.4 update 90 Liferay DXP 7.4 update 90 Liferay Portal 7.4.3.90 Liferay Portal 7.4.3.90 Severity 1...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Liferay DXP 7.3 update 24 Liferay DXP 7.3 update 24 Liferay DXP 7.4 update 79 Liferay Portal 7.4.3.79 Liferay Portal 7.4.3.79 Liferay DXP 7.4 update 79 Severity 2 Stored cross-site scripting (XSS)...
-
Liferay DXP 7.4 before update 54 Liferay Portal 7.4.2 through 7.4.3.53 Liferay DXP 7.4 update 54 Liferay DXP 7.4 update 54 Liferay Portal 7.4.3.54 Liferay Portal 7.4.3.54 Severity 2 Multiple stored...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Liferay Portal 7.4.3.92 This issue was reported by Michael Oelke Severity 1 Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal and Liferay DXP allow...
-
Severity 1 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML into a parent wiki...
-
Severity 2 Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Severity 2 The organization selector in Liferay Portal and Liferay DXP does not check user permission, which allows remote authenticated users to obtain a list of all organizations. Liferay DXP 7.4...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Liferay DXP 7.4 update 70 through 76 Liferay Portal 7.4.3.70 - 7.4.3.76 Liferay DXP 7.4 update 77 Liferay DXP 7.4 update 77 Liferay Portal 7.4.3.77 Liferay Portal 7.4.3.77 This issue was reported...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Liferay Portal 7.4.3.77 This issue was reported by NDIx Severity 2 Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal and Liferay DXP allows remote attackers to...Releases: Liferay Portal 7.4 Liferay DXP 7.4
-
Severity 2 Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the...Releases: Liferay Portal 7.4 Liferay DXP 7.4
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
Found a Security Vulnerability?
There's a different process available if you have a security issue to report...
Hall of Fame!
Raise your profile - report security vulnerabilities and enter the Hall of Fame!
Community
Company
Feedback