Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
liferay liferay portal vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-12645
XSS exists in Liferay Portal prior to 7.0 CE GA4 via an invalid portletId.
Liferay Liferay Portal
4.3
CVSSv2
CVE-2017-12647
XSS exists in Liferay Portal prior to 7.0 CE GA4 via a Knowledge Base article title.
Liferay Liferay Portal
4.3
CVSSv2
CVE-2017-12649
XSS exists in Liferay Portal prior to 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
Liferay Liferay Portal
4.3
CVSSv2
CVE-2016-3670
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay prior to 7.0.0 CE RC1 allows remote malicious users to inject arbitrary web script or HTML via the FirstName field.
Liferay Liferay Portal
1 EDB exploit
4.3
CVSSv2
CVE-2014-2963
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote malicious users to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.
Liferay Liferay Portal 6.1.2 Ce Ga3
Liferay Liferay Portal 6.2.x Ee
Liferay Liferay Portal 6.1.x Ee
4.3
CVSSv2
CVE-2009-3742
Cross-site scripting (XSS) vulnerability in Liferay Portal prior to 5.3.0 allows remote malicious users to inject arbitrary web script or HTML via the p_p_id parameter.
Liferay Liferay Portal
4.3
CVSSv2
CVE-2009-1294
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote malicious users to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.
Novell Teaming 1.0
Novell Teaming 1.0.2
Novell Teaming 1.0.3
Novell Teaming 1.0.1
Liferay Liferay Enterprise Portal 4.3.0
1 EDB exploit
4.3
CVSSv2
CVE-2008-0563
Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote malicious users to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Pa...
Liferay Liferay Enterprise Portal 4.3.6
4.3
CVSSv2
CVE-2008-0180
Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.
Liferay Liferay Enterprise Portal 2.2.0
Liferay Liferay Enterprise Portal 3.6.1
Liferay Liferay Enterprise Portal 4.1
Liferay Liferay Enterprise Portal 4.1.1
Liferay Liferay Enterprise Portal
Liferay Liferay Enterprise Portal 1.0
Liferay Liferay Enterprise Portal 2.1.0
Liferay Liferay Enterprise Portal 4.3.1
Liferay Liferay Enterprise Portal 2.0
Liferay Liferay Enterprise Portal 2.1.1
Liferay Liferay Enterprise Portal 4.1.3
Liferay Liferay Enterprise Portal 4.3.6
4.3
CVSSv2
CVE-2008-0181
Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.
Liferay Liferay Enterprise Portal 4.3.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »