CVE-2024-25143
- EPSS 0.75%
- Published 07.02.2024 15:15:08
- Last modified 21.11.2024 09:00:20
The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generatin...
CVE-2023-47797
- EPSS 0.15%
- Published 17.11.2023 06:15:34
- Last modified 21.11.2024 08:30:49
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
CVE-2023-42627
- EPSS 0.16%
- Published 17.10.2023 13:15:11
- Last modified 21.11.2024 08:22:50
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or H...
CVE-2023-42628
- EPSS 0.16%
- Published 17.10.2023 12:15:10
- Last modified 21.11.2024 08:22:50
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 bef...
CVE-2023-44310
- EPSS 0.15%
- Published 17.10.2023 10:15:09
- Last modified 21.11.2024 08:25:38
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a c...
CVE-2023-44311
- EPSS 0.15%
- Published 17.10.2023 10:15:09
- Last modified 21.11.2024 08:25:38
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attac...
CVE-2023-42629
- EPSS 0.16%
- Published 17.10.2023 09:15:10
- Last modified 21.11.2024 08:22:50
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected...
CVE-2023-44309
- EPSS 0.15%
- Published 17.10.2023 09:15:10
- Last modified 21.11.2024 08:25:38
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload i...
CVE-2023-42497
- EPSS 0.15%
- Published 17.10.2023 08:15:09
- Last modified 21.11.2024 08:22:40
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_lifera...
CVE-2023-3426
- EPSS 0.25%
- Published 02.08.2023 10:15:09
- Last modified 21.11.2024 08:17:14
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.