Liferay

Liferay Portal

180 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 21.02.2024 03:15:09
  • Zuletzt bearbeitet 28.01.2025 02:33:22

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions all...

  • EPSS 0.14%
  • Veröffentlicht 21.02.2024 03:15:09
  • Zuletzt bearbeitet 28.01.2025 02:31:06

Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote...

  • EPSS 0.38%
  • Veröffentlicht 21.02.2024 03:15:08
  • Zuletzt bearbeitet 28.01.2025 02:54:33

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inj...

  • EPSS 0.38%
  • Veröffentlicht 21.02.2024 03:15:08
  • Zuletzt bearbeitet 28.01.2025 02:47:39

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web sc...

  • EPSS 0.39%
  • Veröffentlicht 21.02.2024 03:15:07
  • Zuletzt bearbeitet 28.01.2025 21:18:13

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web...

  • EPSS 0.15%
  • Veröffentlicht 21.02.2024 02:15:30
  • Zuletzt bearbeitet 28.01.2025 21:26:17

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsuppor...

  • EPSS 0.15%
  • Veröffentlicht 21.02.2024 02:15:30
  • Zuletzt bearbeitet 28.01.2025 21:26:27

Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported ver...

  • EPSS 0.19%
  • Veröffentlicht 21.02.2024 02:15:29
  • Zuletzt bearbeitet 28.01.2025 21:25:53

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote a...

  • EPSS 0.15%
  • Veröffentlicht 21.02.2024 02:15:29
  • Zuletzt bearbeitet 28.01.2025 21:26:06

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows re...

  • EPSS 0.09%
  • Veröffentlicht 20.02.2024 22:15:08
  • Zuletzt bearbeitet 13.05.2025 17:19:50

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use ...