Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
liferay digital experience platform vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-33937
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 up to and including 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote malicious users to inject arbitrary web script or HTML via a crafted pay...
Liferay Digital Experience Platform 7.2
Liferay Digital Experience Platform 7.1
Liferay Liferay Portal
NA
CVE-2023-33944
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 up to and including 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into ...
Liferay Digital Experience Platform 7.3
Liferay Digital Experience Platform 7.4
Liferay Liferay Portal
NA
CVE-2023-33945
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 up to and including 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows malicious users to execute arbitrary SQL commands via the name of a database table's p...
Liferay Digital Experience Platform 7.3
Liferay Digital Experience Platform 7.4
Liferay Liferay Portal
312
VMScore
CVE-2022-26593
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 up to and including 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote malicious users to inject arbitrary web script or HTML via the name of a asset ...
Liferay Liferay Portal 7.4.0
Liferay Digital Experience Platform 7.3
Liferay Digital Experience Platform
Liferay Liferay Portal
356
VMScore
CVE-2022-26595
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment U...
Liferay Liferay Portal 7.4.0
Liferay Digital Experience Platform 7.2
Liferay Digital Experience Platform 7.3
Liferay Liferay Portal 7.4.1
Liferay Liferay Portal 7.3.7
445
VMScore
CVE-2022-25146
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing malicious users to exfiltrate the CSRF token via a crafte...
Liferay Liferay Portal
Liferay Digital Experience Platform
312
VMScore
CVE-2021-38265
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 up to and including 7.3.6 allow remote malicious users to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title pa...
Liferay Digital Experience Platform
Liferay Liferay Portal
NA
CVE-2023-42629
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 up to and including 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into a Voca...
Liferay Digital Experience Platform 7.4
Liferay Liferay Portal
NA
CVE-2023-42497
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 up to and including 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote malicious users to inject arbitrary web script or HTML via the `_com_liferay_translatio...
Liferay Digital Experience Platform 7.4
Liferay Liferay Portal
NA
CVE-2023-44309
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 up to and including 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote malicious users to inject arbitrary web script or HTML via a crafted payload injected into...
Liferay Digital Experience Platform 7.4
Liferay Liferay Portal
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »