Liferay

Liferay Portal

180 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Published 20.02.2024 09:15:09
  • Last modified 11.12.2024 14:27:37

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy wi...

  • EPSS 0.24%
  • Published 20.02.2024 08:15:07
  • Last modified 10.12.2024 23:01:58

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated u...

  • EPSS 0.26%
  • Published 20.02.2024 07:15:10
  • Last modified 10.12.2024 23:03:54

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to ...

  • EPSS 0.32%
  • Published 20.02.2024 06:15:07
  • Last modified 28.01.2025 21:34:19

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary exter...

  • EPSS 0.53%
  • Published 20.02.2024 05:15:07
  • Last modified 28.03.2025 21:15:14

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.

  • EPSS 0.33%
  • Published 08.02.2024 04:15:08
  • Last modified 13.05.2025 18:17:51

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if th...

  • EPSS 0.37%
  • Published 08.02.2024 04:15:08
  • Last modified 13.05.2025 18:17:51

In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using ...

  • EPSS 0.32%
  • Published 08.02.2024 04:15:07
  • Last modified 13.05.2025 18:17:51

The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which ...

  • EPSS 0.19%
  • Published 08.02.2024 03:15:07
  • Last modified 21.11.2024 08:30:49

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain...

  • EPSS 0.15%
  • Published 07.02.2024 15:15:09
  • Last modified 13.05.2025 18:17:51

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17...