CVE-2025-2565
- EPSS 0.09%
- Veröffentlicht 20.03.2025 16:10:06
- Zuletzt bearbeitet 20.03.2025 17:15:39
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 all...
CVE-2025-2536
- EPSS 0.21%
- Veröffentlicht 19.03.2025 19:00:42
- Zuletzt bearbeitet 19.03.2025 19:15:50
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 th...
CVE-2021-29038
- EPSS 0.09%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 13.05.2025 17:19:50
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use ...
CVE-2021-29050
- EPSS 0.3%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:35
Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineerin...
CVE-2024-25146
- EPSS 0.33%
- Veröffentlicht 08.02.2024 04:15:08
- Zuletzt bearbeitet 13.05.2025 18:17:51
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if th...
CVE-2024-25148
- EPSS 0.37%
- Veröffentlicht 08.02.2024 04:15:08
- Zuletzt bearbeitet 13.05.2025 18:17:51
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using ...
CVE-2024-25144
- EPSS 0.32%
- Veröffentlicht 08.02.2024 04:15:07
- Zuletzt bearbeitet 13.05.2025 18:17:51
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which ...
CVE-2024-25145
- EPSS 0.15%
- Veröffentlicht 07.02.2024 15:15:09
- Zuletzt bearbeitet 13.05.2025 18:17:51
Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17...
CVE-2023-35030
- EPSS 0.57%
- Veröffentlicht 15.06.2023 05:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:50
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console ...
CVE-2023-35029
- EPSS 0.23%
- Veröffentlicht 15.06.2023 04:15:34
- Zuletzt bearbeitet 21.11.2024 08:07:50
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layo...