Portal
by Liferay
Source repositories
CVEs (327)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26596 | Med | 0.33 | 6.1 | 0.01 | Apr 25, 2022 | Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web… | ||
| CVE-2022-26594 | Med | 0.33 | 6.1 | 0.01 | Apr 15, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder… | ||
| CVE-2021-38264 | Med | 0.33 | 6.1 | 0.01 | Mar 3, 2022 | Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in… | ||
| CVE-2021-38263 | Med | 0.33 | 6.1 | 0.01 | Mar 3, 2022 | Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the… | ||
| CVE-2021-35463 | Med | 0.33 | 6.1 | 0.01 | Aug 4, 2021 | Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. | ||
| CVE-2021-33337 | Med | 0.33 | 6.1 | 0.01 | Aug 4, 2021 | Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the… | ||
| CVE-2021-33326 | Med | 0.33 | 6.1 | 0.01 | Aug 3, 2021 | Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a… | ||
| CVE-2019-16147 | Med | 0.33 | 6.1 | 0.01 | Sep 9, 2019 | Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib. | ||
| CVE-2017-1000425 | Med | 0.33 | 6.1 | 0.01 | Jan 2, 2018 | Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter. | ||
| CVE-2017-12648 | Med | 0.33 | 6.1 | 0.01 | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL. | ||
| CVE-2017-12647 | Med | 0.33 | 6.1 | 0.01 | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title. | ||
| CVE-2017-12646 | Med | 0.33 | 6.1 | 0.01 | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address. | ||
| CVE-2017-12645 | Med | 0.33 | 6.1 | 0.01 | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId. | ||
| CVE-2016-10404 | Med | 0.33 | 6.1 | 0.01 | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp. | ||
| CVE-2021-33325 | Med | 0.32 | 4.9 | 0.01 | Aug 3, 2021 | The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with… | ||
| CVE-2025-43794 | Med | 0.31 | 4.8 | 0.00 | Sep 15, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote… | ||
| CVE-2023-33944 | Med | 0.31 | 4.8 | 0.01 | May 24, 2023 | Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type… | ||
| CVE-2023-33940 | Med | 0.31 | 4.8 | 0.01 | May 24, 2023 | Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL. | ||
| CVE-2023-33938 | Med | 0.31 | 4.8 | 0.01 | May 24, 2023 | Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App… | ||
| CVE-2022-42132 | Med | 0.31 | 5.9 | 0.00 | Nov 15, 2022 | The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the… |
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web…
- risk 0.33cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder…
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in…
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the…
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the…
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a…
- risk 0.33cvss 6.1epss 0.01
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
- risk 0.33cvss 6.1epss 0.01
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
- risk 0.33cvss 6.1epss 0.01
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
- risk 0.33cvss 6.1epss 0.01
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
- risk 0.33cvss 6.1epss 0.01
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
- risk 0.33cvss 6.1epss 0.01
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp.
- risk 0.32cvss 4.9epss 0.01
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with…
- risk 0.31cvss 4.8epss 0.00
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote…
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type…
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App…
- risk 0.31cvss 5.9epss 0.00
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the…
Page 11 of 17