Vulnerabilities (CVE)

Filtered by vendor Liferay Subscribe
Total 196 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33948 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-06-01 N/A 7.5 HIGH
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
CVE-2023-33944 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-06-01 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
CVE-2023-33942 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-06-01 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
CVE-2023-33943 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job Title text field.
CVE-2023-33939 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a facet label.
CVE-2023-33940 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
CVE-2023-33950 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 7.5 HIGH
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
CVE-2023-33949 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 7.5 HIGH
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
CVE-2023-33938 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field.
CVE-2023-33941 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-31 N/A 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
CVE-2023-33937 1 Liferay 2 Digital Experience Platform, Liferay Portal 2023-05-30 N/A 5.4 MEDIUM
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.
CVE-2019-16891 1 Liferay 1 Liferay Portal 2023-02-24 7.5 HIGH 9.8 CRITICAL
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CVE-2022-42123 1 Liferay 2 Digital Experience Platform, Liferay Portal 2022-11-18 N/A 7.5 HIGH
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
CVE-2022-42122 1 Liferay 2 Dxp, Liferay Portal 2022-11-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
CVE-2022-42120 1 Liferay 2 Dxp, Liferay Portal 2022-11-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
CVE-2022-25146 1 Liferay 2 Digital Experience Platform, Liferay Portal 2022-10-28 5.0 MEDIUM 5.3 MEDIUM
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
CVE-2022-41414 1 Liferay 1 Liferay Portal 2022-10-11 N/A 5.3 MEDIUM
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
CVE-2021-38268 1 Liferay 2 Digital Experience Platform, Liferay Portal 2022-10-05 4.0 MEDIUM 6.5 MEDIUM
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.
CVE-2021-38265 1 Liferay 2 Digital Experience Platform, Liferay Portal 2022-07-30 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
CVE-2021-38267 1 Liferay 2 Digital Experience Platform, Liferay Portal 2022-06-16 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle parameter.