Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
liferay vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2012-1712
Directory traversal vulnerability in the Liferay component in Oracle Sun GlassFish Web Space Server prior to 10.0 Update 7 Patch 2 has unknown impact and attack vectors.
Oracle Glassfish Web Space Server10.0 Update 7
9
CVSSv2
CVE-2020-28884
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administr...
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3.5
9
CVSSv2
CVE-2020-28885
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it i...
Liferay Liferay Portal 7.2
Liferay Liferay Portal 7.3.5
9
CVSSv2
CVE-2019-11444
An issue exists in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_script value to group/contr...
Liferay Liferay Portal 7.1.2
7.5
CVSSv2
CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal before 7.2.1 CE GA2 allows remote malicious users to execute arbitrary code via JSON web services (JSONWS).
Liferay Liferay Portal
13 Github repositories
7.5
CVSSv2
CVE-2019-16891
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Liferay Liferay Portal 7.1.0
Liferay Liferay Portal 7.0.6
Liferay Liferay Portal 7.0.5
Liferay Liferay Portal 7.0.4
Liferay Liferay Portal 7.0.3
Liferay Liferay Portal 7.0.2
Liferay Liferay Portal 7.0.1
Liferay Liferay Portal 7.0.0
Liferay Liferay Portal 6.2.5
Liferay Liferay Portal 6.2.4
Liferay Liferay Portal 6.2.3
Liferay Liferay Portal 6.2.2
Liferay Liferay Portal 6.2.1
Liferay Liferay Portal 6.2.0
Liferay Liferay Portal 6.1.2
Liferay Liferay Portal 6.1.1
Liferay Liferay Portal 6.1.0
Liferay Liferay Portal
Liferay Liferay Portal 7.1.1
Liferay Liferay Portal 7.1.2
Liferay Liferay Portal 7.1.3
Liferay Liferay Portal 7.2.0
7.5
CVSSv2
CVE-2016-6517
Directory traversal vulnerability in Liferay 5.1.0 allows remote malicious users to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.
Liferay Liferay 5.1.0
6.8
CVSSv2
CVE-2020-15842
Liferay Portal prior to 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle malicious users to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
Liferay Dxp 7.0
Liferay Dxp 7.1
Liferay Dxp 7.2
Liferay Liferay Portal
6.8
CVSSv2
CVE-2011-1571
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x prior to 6.0.6 GA, when Apache Tomcat is used, allows remote malicious users to execute arbitrary commands via unknown vectors.
Liferay Liferay Portal
1 EDB exploit
1 Github repository
6.5
CVSSv2
CVE-2021-33335
Privilege escalation vulnerability in Liferay Portal 7.0.3 up to and including 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by edit...
Liferay Dxp 7.2
Liferay Dxp 7.1
Liferay Liferay Portal
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »