VYPR

Maven package

com.liferay/com.liferay.object.web

pkg:maven/com.liferay/com.liferay.object.web

Vulnerabilities (2)

  • CVE-2025-43758Aug 22, 2025
    affected < 1.0.219fixed 1.0.219

    Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access

  • CVE-2022-42115Oct 18, 2022
    affected < 1.0.99fixed 1.0.99

    Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.