Planned maintenance is scheduled for the week of June 15th - the exact date and time will be announced soon. See More Details
Known Vulnerabilities
Severity 1 Pattern Redirects in Liferay Portal and Liferay DXP allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an...
Liferay Portal 7.3.1 Severity 2 In Liferay Portal and Liferay DXP the default configuration does not require users to verify their email address, which allows remote attackers to create accounts...
Liferay Portal 7.4.3.61 Severity 2 The Object module in Liferay Portal and Liferay DXP does not segment object definition by virtual instance in search which allows remote authenticated users in...
Severity 2 The Object module in Liferay Portal and Liferay DXP does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view...
Severity 2 Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload...
Liferay Portal 7.4.3.53 Severity 2 Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal and Liferay DXP...
Severity 2 Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the Remote App's...
Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected...
Severity 2 Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal and Liferay DXP allows remote attackers to inject arbitrary web script...
Liferay Portal 7.3.1 Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal, and Liferay DXP allows remote attackers to inject arbitrary web script or HTML...
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.2 does not validate HTTPS certificates used with DDMRESTDataProvider, which allows man-in-the-middle attackers to impersonate,...
Severity 2 The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4 does not properly check permission of form entries, which allows remote authenticated users to view and access all...
Severity 2 Liferay Portal 7.4.3.5 There is no fix available for Liferay Portal 7.3. Please upgrade to Liferay Portal 7.4. Liferay Portal 7.3.2 - 7.3.7 Liferay Portal 7.4.0 - 7.4.3.4 Liferay Portal...
Severity 2 The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4 does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the...
Severity 2 The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36 does not properly check user permission, which allows remote attackers to obtain the history of all friendly URLs that...
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the...
Liferay Portal 7.4.3.36 Liferay Portal 7.4.3.36 Severity 2 Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 allows attackers to create or overwrite existing files...
ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 allows remote attackers to consume an excessive amount of server resources via a crafted payload...
Severity 2 Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18 allows attackers to create or overwrite existing files on the filesystem via the...
Liferay Portal 7.4.0 There is no fix available for Liferay Portal 7.3. Please upgrade to Liferay Portal 7.4. Liferay Portal 7.3.7 Liferay Portal 7.4.0 SQL injection vulnerability in the Friendly...
Severity 2 SQL injection vulnerability in the Layout module's page template upgrade process in Liferay Portal 7.1.3 through 7.4.3.4 allows remote authenticated attackers to execute arbitrary SQL...
SQL injection vulnerability in the Fragment module's PortletPreferences upgrade process in Liferay Portal 7.3.3 through 7.4.3.16 allows attackers to execute arbitrary SQL commands via a...
Liferay Portal 7.3.5 - 7.3.7 Liferay Portal 7.4.0 - 7.4.2 Liferay Portal 7.4.3.4 Liferay Portal 7.4.3.4 There is no fix available for Liferay Portal 7.3. Please upgrade to Liferay Portal 7.4. This...
Severity 2 Cross-site scripting (XSS) vulnerability in the Portal Search module's Tag Facet widget in Liferay Portal 7.1.0 through 7.4.2 allows remote attackers to inject arbitrary web script or...
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module's <clay:label> tag in Liferay Portal 7.3.2 through 7.4.3.16 allows remote attackers to inject arbitrary web script or HTML via...
Severity 2 Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14 allows remote attackers to inject arbitrary...
Liferay Portal 7.4.3.37 Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject...
Severity 2 Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36 allows remote attackers to inject arbitrary web script or...
Cross-site scripting (XSS) vulnerability in Document Library module's move file interface in Liferay Portal 7.4.3.30 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML...
Liferay Portal 7.4.3.25 Liferay Portal 7.4.3.25 There is no fix available for Liferay Portal 7.2 and 7.3. Please upgrade to Liferay Portal 7.4. Severity 2 Cross-site scripting (XSS) vulnerability...
Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2 allows remote attackers to inject arbitrary web script or HTML by sharing an...
Severity 2 Cross-site scripting (XSS) vulnerability in the Announcements module's Announcement and Alerts management page in Liferay Portal 7.1.0 through 7.4.2 allows remote attackers to inject...
Liferay Portal 7.3.5 - 7.3.7 Liferay Portal 7.4.0 - 7.4.3.28 Liferay Portal 7.4.3.29 Liferay Portal 7.4.3.29 There is no fix available for Liferay Portal 7.3. Please upgrade to Liferay Portal 7.4....
This issue was reported by Rafal Lykowski, A1 Digital International Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector input field in Liferay Portal 7.3.0...
Severity 2 The Layout module in Liferay Portal 7.3.3 through 7.4.3.34 does not check user permission before showing the preview of a "Content Page" type page, which allows remote attackers to view...
Found a Bug?
If you have found, or think you have found a bug, help us to help you by letting us know!
This website uses cookies and similar tools, some of which are provided by third parties (together “tools”). These tools enable us and the third parties to access and record certain user-related and activity data and to track your interactions with this website. These tools and the information collected are used to operate and secure this website, enhance performance, enable certain website features and functionality, analyze and improve website performance, and personalize user experience.
If you click "Accept All”, you allow the deployment of all these tools and collection of the information by us and the third parties for all these purposes.
If you click “Decline All” your IP address and other information may still be collected but only by tools (including third party tools) that are necessary to operate, secure and enable default website features and functionalities. Review and change your preferences by clicking the “Configurations” at any time.
Visit our Privacy Policy