CVE-2025-3602
- EPSS 0.17%
- Veröffentlicht 16.06.2025 13:50:04
- Zuletzt bearbeitet 17.06.2025 20:50:23
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attacker...
CVE-2025-4388
- EPSS 4.48%
- Veröffentlicht 06.05.2025 18:15:39
- Zuletzt bearbeitet 07.05.2025 14:13:20
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through ...
CVE-2025-3760
- EPSS 0.18%
- Veröffentlicht 17.04.2025 12:53:19
- Zuletzt bearbeitet 17.04.2025 20:21:48
A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1...
CVE-2025-2565
- EPSS 0.13%
- Veröffentlicht 20.03.2025 16:10:06
- Zuletzt bearbeitet 20.03.2025 17:15:39
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 all...
CVE-2025-2536
- EPSS 0.29%
- Veröffentlicht 19.03.2025 19:00:42
- Zuletzt bearbeitet 19.03.2025 19:15:50
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 th...
CVE-2021-29038
- EPSS 0.09%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 13.05.2025 17:19:50
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use ...
CVE-2021-29050
- EPSS 0.3%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:35
Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineerin...
CVE-2024-25146
- EPSS 0.33%
- Veröffentlicht 08.02.2024 04:15:08
- Zuletzt bearbeitet 13.05.2025 18:17:51
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if th...
CVE-2024-25148
- EPSS 0.37%
- Veröffentlicht 08.02.2024 04:15:08
- Zuletzt bearbeitet 13.05.2025 18:17:51
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using ...
CVE-2024-25144
- EPSS 0.32%
- Veröffentlicht 08.02.2024 04:15:07
- Zuletzt bearbeitet 13.05.2025 18:17:51
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which ...