Skip to main content

Vendor/product archive

liferay / liferay_portal CVEs

Beta · best-effort

319 CVEs tagged to liferay / liferay_portal28 Critical, 37 High, 242 Medium, 12 Low, 0 Unrated.

CVE-2021-29052

Published May 17, 2021

The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionB…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29053

Published May 17, 2021

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the cla…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29046

Published May 17, 2021

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29045

Published May 17, 2021

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29047

Published May 16, 2021

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29039

Published May 16, 2021

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTM…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25476

Published Jan 7, 2021

Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24554

Published Sep 1, 2020

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13445

Published Jun 10, 2020

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensiti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13444

Published Jun 10, 2020

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7961

Published Mar 20, 2020

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
59.2
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-7934

Published Jan 28, 2020

In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16891

Published Oct 4, 2019

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16147

Published Sep 9, 2019

Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6588

Published Jun 3, 2019

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 319 CVEsPage 12 of 13