CVE-2011-1504

Liferay Portal CE <6.0.6 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-79
Status published

Affected Products (16)

liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
liferay/portal
... and 1 more

Timeline

Published May 07, 2011
Tracked Since Feb 18, 2026