Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
liferay dxp 7.0 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-29044
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 up to and including 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows re...
Liferay Dxp 7.0
Liferay Dxp 7.2
Liferay Dxp 7.1
Liferay Dxp 7.3
Liferay Liferay Portal
5.3
CVSSv3
CVE-2021-29040
The JSON web services in Liferay Portal 7.3.4 and previous versions, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote malicious users to use the contents of error messages to h...
Liferay Dxp 7.0
Liferay Dxp 7.2
Liferay Dxp 7.1
Liferay Dxp
Liferay Liferay Portal
5.3
CVSSv3
CVE-2020-15840
In Liferay Portal prior to 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
Liferay Dxp 7.0
Liferay Dxp 7.1
Liferay Dxp 7.2
Liferay Liferay Portal 6.2
Liferay Liferay Portal
8.8
CVSSv3
CVE-2020-15841
Liferay Portal prior to 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote malicious users to obtain the LDAP server's password via the Test LDAP Connection...
Liferay Liferay Portal
Liferay Dxp 7.0
Liferay Dxp 7.1
Liferay Dxp 7.2
8.1
CVSSv3
CVE-2020-15842
Liferay Portal prior to 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle malicious users to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
Liferay Liferay Portal
Liferay Dxp 7.0
Liferay Dxp 7.2
Liferay Dxp 7.1
8.8
CVSSv3
CVE-2020-13445
In Liferay Portal prior to 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarke...
Liferay Liferay Portal 7.1.1
Liferay Liferay Portal 7.1
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3
1 Github repository
6.5
CVSSv3
CVE-2020-13444
Liferay Portal 7.x prior to 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Provider...
Liferay Liferay Portal 7.1.1
Liferay Liferay Portal 7.1
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3