liferay

340 tracked vulnerabilities.

CVE-2020-15841 HIGH
Liferay Portal <7.3.0 & Liferay DXP <7.0-7.2 - Info Disclosure
Jul 20, 2020
CVSS 8.3
EPSS 0.00
CVE-2020-13445 HIGH
Liferay Portal <7.3.2 & DXP 7.0-7.2 - RCE
Jun 10, 2020
CVSS 8.8
EPSS 0.04
CVE-2020-13444 MEDIUM
Liferay Portal/DXP <7.3.2/7.0-7.1-7.2 - Info Disclosure
Jun 10, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-7961 CRITICAL KEVNUCLEI
Liferay Portal <7.2.1 CE GA2 - Code Injection
Mar 20, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-7934 MEDIUM
Liferay Portal 7.1.0-7.2.1 GA2 - Stored Cross-Site Scripting in User Account Name Fields
Jan 28, 2020
CVSS 5.4
EPSS 0.03
CVE-2019-16891 CRITICAL
Liferay Portal CE 6.2.5 - Code Injection
Oct 04, 2019
CVSS 9.8
EPSS 0.80
CVE-2019-16147 MEDIUM
Liferay Portal < 7.2.0 - Cross-Site Scripting via Journal Article Title
Sep 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-6588 MEDIUM
Liferay Portal < 7.1 CE GA4 - Cross-Site Scripting via SimpleCaptcha URL Parameter
Jun 03, 2019
CVSS 4.7
EPSS 0.01
CVE-2019-11444 HIGH
Liferay Portal CE 7.1.2 GA3 - Command Injection
Apr 22, 2019
CVSS 7.2
EPSS 0.37
CVE-2018-10795 HIGH
Liferay Portal < 6.2.5 - Authenticated Unrestricted Upload of File with Dangerous Type via FCKeditor Configuration
May 07, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-1000425 MEDIUM
Liferay Portal < 7.0.3_ga4 - Cross-Site Scripting via Flash.jsp Movie Parameter
Jan 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-17868 MEDIUM
Liferay Portal 6.1.0 - Cross-Site Scripting via Public Render Parameter
Dec 27, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-12649 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Web Content Display Title or Summary
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-12648 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Bookmark URL
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-12647 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Knowledge Base Article Title
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-12646 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Login Name, Password, or Email Address
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-12645 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Invalid PortletId
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-10404 MEDIUM
Liferay Portal < 7.0 - Cross-Site Scripting via Redirect Field in init.jsp
Aug 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6517 CRITICAL
Liferay 5.1.0 - Path Traversal via minifierBundleDir Parameter
Jan 23, 2017
CVSS 9.8
EPSS 0.01
CVE-2016-3670 MEDIUM
Liferay Portal < 6.2 - Stored Cross-Site Scripting via Profile Search FirstName Field
Jun 13, 2016
CVSS 6.1
EPSS 0.09
CVE-2014-8349
Liferay Portal < 6.2 - Authenticated Cross-Site Scripting via Comment Field
Nov 24, 2014
EPSS 0.00
CVE-2014-2963
Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE - Stored Cross-Site Scripting via User Name Parameters
Jul 10, 2014
EPSS 0.01
CVE-2011-1571
Liferay Portal 5.1.0-5.1.1 and 5.0.0-6.0.5 - Remote Code Execution in XSL Content Portlet
May 07, 2011
EPSS 0.07
CVE-2011-1570
Liferay Portal 6.0.0-6.0.5 - Authenticated Cross-Site Scripting via Message Title
May 07, 2011
EPSS 0.01
CVE-2011-1504
Liferay Portal 5.x and 6.x < 6.0.6 GA - Authenticated Cross-Site Scripting via Blog Title
May 07, 2011
EPSS 0.00