Liferay

Digital Experience Platform

186 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 20.02.2024 05:15:07
  • Zuletzt bearbeitet 28.03.2025 21:15:14

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.

  • EPSS 0.33%
  • Veröffentlicht 08.02.2024 04:15:08
  • Zuletzt bearbeitet 13.05.2025 18:17:51

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if th...

  • EPSS 0.37%
  • Veröffentlicht 08.02.2024 04:15:08
  • Zuletzt bearbeitet 13.05.2025 18:17:51

In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using ...

  • EPSS 0.32%
  • Veröffentlicht 08.02.2024 04:15:07
  • Zuletzt bearbeitet 13.05.2025 18:17:51

The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which ...

  • EPSS 0.19%
  • Veröffentlicht 08.02.2024 03:15:07
  • Zuletzt bearbeitet 21.11.2024 08:30:49

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain...

  • EPSS 0.15%
  • Veröffentlicht 07.02.2024 15:15:09
  • Zuletzt bearbeitet 13.05.2025 18:17:51

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17...

  • EPSS 0.75%
  • Veröffentlicht 07.02.2024 15:15:08
  • Zuletzt bearbeitet 21.11.2024 09:00:20

The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generatin...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 17.10.2023 13:15:11
  • Zuletzt bearbeitet 21.11.2024 08:22:50

Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or H...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 17.10.2023 12:15:10
  • Zuletzt bearbeitet 21.11.2024 08:22:50

Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 bef...

  • EPSS 0.2%
  • Veröffentlicht 17.10.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 08:25:38

Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a c...