Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
liferay liferay portal 7.2.0 vulnerabilities and exploits
(subscribe to this query)
9
CVSSv2
CVE-2020-28884
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administr...
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3.5
9
CVSSv2
CVE-2020-28885
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it i...
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3.5
7.5
CVSSv2
CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal before 7.2.1 CE GA2 allows remote malicious users to execute arbitrary code via JSON web services (JSONWS).
Liferay Liferay Portal
13 Github repositories
7.5
CVSSv2
CVE-2019-16891
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Liferay Liferay Portal 7.1.0
Liferay Liferay Portal 7.0.6
Liferay Liferay Portal 7.0.5
Liferay Liferay Portal 7.0.4
Liferay Liferay Portal 7.0.3
Liferay Liferay Portal 7.0.2
Liferay Liferay Portal 7.0.1
Liferay Liferay Portal 7.0.0
Liferay Liferay Portal 6.2.5
Liferay Liferay Portal 6.2.4
Liferay Liferay Portal 6.2.3
Liferay Liferay Portal 6.2.2
Liferay Liferay Portal 6.2.1
Liferay Liferay Portal 6.2.0
Liferay Liferay Portal 6.1.2
Liferay Liferay Portal 6.1.1
Liferay Liferay Portal 6.1.0
Liferay Liferay Portal
Liferay Liferay Portal 7.1.1
Liferay Liferay Portal 7.1.2
Liferay Liferay Portal 7.1.3
Liferay Liferay Portal 7.2.0
4.3
CVSSv2
CVE-2021-33330
Liferay Portal 7.2.0 up to and including 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote malicious users to obtai...
Liferay Dxp 7.2
Liferay Liferay Portal
4.3
CVSSv2
CVE-2019-16147
Liferay Portal up to and including 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
Liferay Liferay Portal 7.2.0
Liferay Liferay Portal
4
CVSSv2
CVE-2021-33327
The Portlet Configuration module in Liferay Portal 7.2.0 up to and including 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User...
Liferay Dxp 7.0
Liferay Dxp 7.1
Liferay Dxp 7.2
Liferay Liferay Portal
NA
CVE-2024-25151
The Calendar module in Liferay Portal 7.2.0 up to and including 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, ...
NA
CVE-2024-26266
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 up to and including 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenti...
NA
CVE-2024-26269
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 up to and including 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote malicious us...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-17519
open redirect
CVE-2024-21683
cache poisoning
CVE-2021-47524
CVE-2021-47521
CVE-2024-5229
CVE-2021-47560
local
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »