Liferay

Liferay Portal

180 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Published 21.02.2024 03:15:09
  • Last modified 28.01.2025 02:33:22

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions all...

  • EPSS 0.14%
  • Published 21.02.2024 03:15:09
  • Last modified 28.01.2025 02:31:06

Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote...

  • EPSS 0.38%
  • Published 21.02.2024 03:15:08
  • Last modified 28.01.2025 02:54:33

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inj...

  • EPSS 0.38%
  • Published 21.02.2024 03:15:08
  • Last modified 28.01.2025 02:47:39

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web sc...

  • EPSS 0.39%
  • Published 21.02.2024 03:15:07
  • Last modified 28.01.2025 21:18:13

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web...

  • EPSS 0.15%
  • Published 21.02.2024 02:15:30
  • Last modified 28.01.2025 21:26:17

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsuppor...

  • EPSS 0.15%
  • Published 21.02.2024 02:15:30
  • Last modified 28.01.2025 21:26:27

Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported ver...

  • EPSS 0.19%
  • Published 21.02.2024 02:15:29
  • Last modified 28.01.2025 21:25:53

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote a...

  • EPSS 0.15%
  • Published 21.02.2024 02:15:29
  • Last modified 28.01.2025 21:26:06

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows re...

  • EPSS 0.09%
  • Published 20.02.2024 22:15:08
  • Last modified 13.05.2025 17:19:50

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use ...