VYPR

Maven package

com.liferay/com.liferay.frontend.taglib.clay

pkg:maven/com.liferay/com.liferay.frontend.taglib.clay

Vulnerabilities (4)

  • CVE-2025-43734Aug 12, 2025
    affected < 15.2.2fixed 15.2.2

    A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA throu

  • CVE-2022-42117Oct 18, 2022
    affected < 9.1.7fixed 9.1.7

    A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2021-38264Mar 2, 2022
    affected < 7.1.15fixed 7.1.15

    Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CV

  • CVE-2021-35463Aug 4, 2021
    affected < 7.1.15fixed 7.1.15

    Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.