Skip to main content

Vendor/product archive

liferay / dxp CVEs

Beta · best-effort

39 CVEs tagged to liferay / dxp3 Critical, 5 High, 31 Medium, 0 Low, 0 Unrated.

CVE-2023-35030

Published Jun 15, 2023

Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35029

Published Jun 15, 2023

Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42122

Published Nov 15, 2022

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL command…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42120

Published Nov 15, 2022

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42119

Published Nov 15, 2022

Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38901

Published Oct 19, 2022

A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42117

Published Oct 18, 2022

A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 al…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42116

Published Oct 18, 2022

A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42114

Published Oct 18, 2022

A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42113

Published Oct 18, 2022

A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote at…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38902

Published Oct 13, 2022

A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arb…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38512

Published Sep 22, 2022

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28980

Published Sep 22, 2022

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters wit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39975

Published Sep 22, 2022

The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the prev…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28982

Published Sep 22, 2022

A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2