CVE-2025-2565
- EPSS 0.1%
- Veröffentlicht 20.03.2025 16:10:06
- Zuletzt bearbeitet 16.12.2025 18:44:27
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 all...
CVE-2025-2536
- EPSS 0.06%
- Veröffentlicht 19.03.2025 19:00:42
- Zuletzt bearbeitet 16.12.2025 18:43:10
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 th...
CVE-2023-37940
- EPSS 0.13%
- Veröffentlicht 17.12.2024 22:15:05
- Zuletzt bearbeitet 28.01.2025 21:18:48
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to in...
CVE-2024-11993
- EPSS 0.08%
- Veröffentlicht 17.12.2024 21:15:07
- Zuletzt bearbeitet 28.03.2025 20:15:20
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
CVE-2024-8980
- EPSS 0.28%
- Veröffentlicht 22.10.2024 15:15:07
- Zuletzt bearbeitet 10.12.2024 21:07:09
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2...
CVE-2024-38002
- EPSS 3.19%
- Veröffentlicht 22.10.2024 15:15:06
- Zuletzt bearbeitet 10.09.2025 16:15:34
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating...
CVE-2024-26271
- EPSS 1.49%
- Veröffentlicht 22.10.2024 15:15:05
- Zuletzt bearbeitet 10.12.2024 21:07:04
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through...
CVE-2024-26272
- EPSS 4.61%
- Veröffentlicht 22.10.2024 15:15:05
- Zuletzt bearbeitet 10.12.2024 21:07:02
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allo...
CVE-2024-26273
- EPSS 1.49%
- Veröffentlicht 22.10.2024 15:15:05
- Zuletzt bearbeitet 10.12.2024 21:07:07
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update ...
CVE-2023-47795
- EPSS 0.39%
- Veröffentlicht 21.02.2024 14:15:45
- Zuletzt bearbeitet 28.01.2025 21:17:39
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary ...