Medium severity6.1NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026
CVE-2019-16147
CVE-2019-16147
Description
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay:com.liferay.journal.taglibMaven | < 3.0.4 | 3.0.4 |
Affected products
11cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*range: <7.2.0
- cpe:2.3:a:liferay:liferay_portal:7.2.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:ga1:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:liferay:liferay_portal:7.2.0:rc3:*:*:*:*:*:*
- Liferay/Liferay Portaldescription
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.