CVE-2024-25151
- EPSS 0.36%
- Veröffentlicht 21.02.2024 04:15:08
- Zuletzt bearbeitet 28.01.2025 02:28:11
The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notificatio...
CVE-2024-25603
- EPSS 0.15%
- Veröffentlicht 21.02.2024 03:15:09
- Zuletzt bearbeitet 28.01.2025 02:39:55
Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsup...
CVE-2024-26266
- EPSS 0.2%
- Veröffentlicht 21.02.2024 03:15:09
- Zuletzt bearbeitet 28.01.2025 02:33:22
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions all...
CVE-2024-26269
- EPSS 0.14%
- Veröffentlicht 21.02.2024 03:15:09
- Zuletzt bearbeitet 28.01.2025 02:31:06
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote...
CVE-2023-42496
- EPSS 0.38%
- Veröffentlicht 21.02.2024 03:15:08
- Zuletzt bearbeitet 28.01.2025 02:54:33
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inj...
CVE-2023-42498
- EPSS 0.38%
- Veröffentlicht 21.02.2024 03:15:08
- Zuletzt bearbeitet 28.01.2025 02:47:39
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web sc...
CVE-2023-40191
- EPSS 0.39%
- Veröffentlicht 21.02.2024 03:15:07
- Zuletzt bearbeitet 28.01.2025 21:18:13
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web...
CVE-2024-25601
- EPSS 0.15%
- Veröffentlicht 21.02.2024 02:15:30
- Zuletzt bearbeitet 28.01.2025 21:26:17
Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsuppor...
CVE-2024-25602
- EPSS 0.15%
- Veröffentlicht 21.02.2024 02:15:30
- Zuletzt bearbeitet 28.01.2025 21:26:27
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported ver...
CVE-2024-25147
- EPSS 0.19%
- Veröffentlicht 21.02.2024 02:15:29
- Zuletzt bearbeitet 28.01.2025 21:25:53
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote a...