Liferay

Portal

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 29.09.2025 22:15:35
  • Zuletzt bearbeitet 02.10.2025 19:12:42

Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML...

  • EPSS 0.17%
  • Veröffentlicht 29.09.2025 22:15:35
  • Zuletzt bearbeitet 02.10.2025 19:12:42

Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update ...

  • EPSS 0.17%
  • Veröffentlicht 29.09.2025 22:15:34
  • Zuletzt bearbeitet 02.10.2025 19:12:42

Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows ...

  • EPSS 0.06%
  • Veröffentlicht 25.09.2025 20:15:34
  • Zuletzt bearbeitet 26.09.2025 14:32:19

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA throug...

  • EPSS 0.04%
  • Veröffentlicht 24.09.2025 02:15:31
  • Zuletzt bearbeitet 24.09.2025 18:11:24

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an r...

  • EPSS 0.2%
  • Veröffentlicht 24.09.2025 01:15:30
  • Zuletzt bearbeitet 24.09.2025 18:11:24

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_li...

  • EPSS 0.14%
  • Veröffentlicht 22.09.2025 23:15:37
  • Zuletzt bearbeitet 24.09.2025 18:11:34

Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authentic...

  • EPSS 0.18%
  • Veröffentlicht 22.09.2025 23:15:37
  • Zuletzt bearbeitet 24.09.2025 18:11:34

In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password ...

  • EPSS 0.15%
  • Veröffentlicht 22.09.2025 22:15:43
  • Zuletzt bearbeitet 24.09.2025 18:11:34

Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authe...

  • EPSS 0.17%
  • Veröffentlicht 22.09.2025 16:17:24
  • Zuletzt bearbeitet 22.09.2025 21:22:33

Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to ...